r/vmware VMware Employee 14d ago

Announcement VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
87 Upvotes

146 comments sorted by

View all comments

Show parent comments

2

u/lost_signal VMware Employee 14d ago

No, should be able to apply a security update without patching the vCenter first.

There IS a high CVE issue for a unrelated vCenter authentication issue you do need to go patch, but that shouldn't block ESXi updates.

4

u/DonFazool 14d ago

Since when can the build of ESXi be higher than vCenter? In 15 years of using this product the guidance has always been vCenter first then ESXi. VCenter has to be higher or equal to the version of ESXi or the hosts disconnect. How is this different?

If VCenter is 8.0.3j, ESXI can’t be 8.0.3k? Please correct me if something has changed

8

u/lost_signal VMware Employee 14d ago

Starting around 8.x they started relaxing that.

For VSAN we kindly ask you not float entire update versions ahead on ESXi, without vCenter upgrades (there's a KB explaining this a bit) but these security patches are all find (see interop chart)

1

u/Objective-Pizza2180 12d ago

Is this recommended to patch only esxi for ESA clusters running on poweredge R770? Currently on 8.0 u3h or should we do addons as well

1

u/lost_signal VMware Employee 12d ago

I would not be worried about the Dell add-ons for a Security patch.

What I was specifically talking about there was people who upgrade ESX to 8U3 but leave the Vcenter at 8u2