Record summary

CVE-2026-41709 has a selected CVSS score of 2.7 (low).

Description

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 30, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List9.1.x.xaffected
9.0.x.xaffected
5.x to < 5.2.4affected

Default status: unaffected

CVE List9.1.x.x to < ESXi-9.1.0.0-25370933affected
9.0.x.x to < ESXi-9.0.2.0100-25595025affected
8.0 to < ESXi80U3j-25429389affected

Default status: unaffected

CVE List5.1.xaffected
5.0.xaffected

Default status: unaffected

CVE List9.1.x.xaffected
9.0.x.xaffected

Research & analysis

1
Advisory analysisSocuraSource: EIP research review

VMSA-2026-0006: Multiple VMware ESX, vCenter, Workstation and Fusion Vulnerabilities

Socura threat alert analyzing Broadcom's VMSA-2026-0006 advisory covering five VMware vulnerabilities. CVE-2026-59309: authentication bypass in vCenter's VMware Directory Service (vmdir) via crafted network traffic, enabling unauthenticated administrative session takeover. CVE-2026-59310: directory traversal in the vCenter Syslog daemon allowing unauthenticated attackers to submit log messages with path traversal sequences, escaping the syslog directory to achieve root-level code execution on the vCSA. CVE-2026-47876: out-of-bounds write in VMXNET3 buffer allocation enabling guest-to-host VM escape from a compromised VM with local admin access; VMs using non-VMXNET3 adapters are unaffected. CVE-2026-41703: out-of-bounds read during VM creation causing host process termination (DoS) or memory disclosure on ESX, limited to information disclosure on Workstation/Fusion. CVE-2026-41709: insufficient logging allowing a malicious ESXi administrator to perform operations without audit records, enabling stealthy post-exploitation persistence. The source describes two attack chains: top-down (external attacker compromises vCenter via CVE-2026-59309 or CVE-2026-59310 to gain management-plane control) and bottom-up (attacker with guest VM admin access exploits CVE-2026-47876 for VM escape, then uses CVE-2026-41709 for audit log evasion). No workarounds exist; patching to fixed versions is required. The source does not claim active exploitation or public PoC availability.

Root causeExploit chainTechnical detail
https://socura.co.uk/threat-alerts/vmsa-2026-0006-multiple-vmware-esx-vcenter-workstation-and-fusion-vulnerabilities
Research notes

References

1