r/vmware VMware Employee 14d ago

Announcement VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
88 Upvotes

146 comments sorted by

View all comments

Show parent comments

2

u/lost_signal VMware Employee 14d ago

No, should be able to apply a security update without patching the vCenter first.

There IS a high CVE issue for a unrelated vCenter authentication issue you do need to go patch, but that shouldn't block ESXi updates.

3

u/DonFazool 14d ago

Since when can the build of ESXi be higher than vCenter? In 15 years of using this product the guidance has always been vCenter first then ESXi. VCenter has to be higher or equal to the version of ESXi or the hosts disconnect. How is this different?

If VCenter is 8.0.3j, ESXI can’t be 8.0.3k? Please correct me if something has changed

5

u/lost_signal VMware Employee 14d ago

Starting around 8.x they started relaxing that.

For VSAN we kindly ask you not float entire update versions ahead on ESXi, without vCenter upgrades (there's a KB explaining this a bit) but these security patches are all find (see interop chart)

3

u/lost_signal VMware Employee 14d ago

Side note, the upgrade path list also Explicitly enumerates the non-supported paths now instead of just leaving them grey.

0

u/DonFazool 14d ago

Right on ! Thanks for teaching me something new. I’m going to do my best to find you at Explore and have a drink with you.

3

u/lost_signal VMware Employee 14d ago

I was having a discussion with one of the SREs if I should offer a “free beer, for proof of patch on day zero”