CVE-2026-41703
HIGHVmware Cloud Foundation < 9.1.x.x - Denial of Service
Title source: ruleDescription
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
References (1)
Core 1
Scores
CVSS v3
7.6
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (12)
VMware/Cloud Foundation
5.x - 5.2.3
VMware/Cloud Foundation
9.0.x.x
VMware/Cloud Foundation
9.1.x.x
VMware/ESX
8.0 - ESXi80U3i-25205845
VMware/ESX
9.0.x.x - ESXi-9.0.2.0100-25595025
VMware/ESX
9.1.x.x - ESXi-9.1.0.0-25370933
VMware/Fusion
25H2 - 26H1
VMware/Telco Cloud Platform
5.0.x
VMware/Telco Cloud Platform
5.1.x
VMware/vSphere Foundation
9.0.x.x
... and 2 more
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026