CVE-2026-41703

HIGH

Vmware Cloud Foundation < 9.1.x.x - Denial of Service

Title source: rule
STIX 2.1

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Scores

CVSS v3 7.6
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (12)
VMware/Cloud Foundation 5.x - 5.2.3
VMware/Cloud Foundation 9.0.x.x
VMware/Cloud Foundation 9.1.x.x
VMware/ESX 8.0 - ESXi80U3i-25205845
VMware/ESX 9.0.x.x - ESXi-9.0.2.0100-25595025
VMware/ESX 9.1.x.x - ESXi-9.1.0.0-25370933
VMware/Fusion 25H2 - 26H1
VMware/Telco Cloud Platform 5.0.x
VMware/Telco Cloud Platform 5.1.x
VMware/vSphere Foundation 9.0.x.x
... and 2 more
Published Jul 30, 2026
Tracked Since Jul 30, 2026