[CIVN-2026-0386] Multiple Vulnerabilities in VMware Products

By Published On: August 5, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in VMware Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


VMware vCenter Server 8.0 versions prior to 8.0 U3e

VMware vCenter Server 7.0 versions prior to 7.0 U3v

VMware ESXi 8.0 versions prior to ESXi80U3e

VMware ESXi 7.0 versions prior to ESXi70U3v

VMware Workstation Pro 17.x versions prior to 17.6.4

VMware Fusion 13.x versions prior to 13.6.4

VMware Cloud Foundation deployments containing the affected versions of VMware ESXi and VMware vCenter Server

VMware Telco Cloud Platform deployments containing the affected versions of VMware ESXi and VMware vCenter Server

VMware Telco Cloud Infrastructure deployments containing the affected versions of VMware ESXi and VMware vCenter Server

Overview


Multiple vulnerabilities have been reported in VMware products, which could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, or cause denial of service on the affected systems.


Target Audience:

All organizations and individuals using the affected VMware products.


Risk Assessment:

High risk of arbitrary code execution, privilege escalation, unauthorized file operations, sensitive information disclosure, and denial of service.


Impact Assessment:

Successful exploitation of these vulnerabilities could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, cause denial of service, and compromise the confidentiality, integrity, and availability of the affected systems.


Description


VMware ESXi, VMware vCenter Server, VMware Workstation Pro, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure are virtualization and cloud infrastructure products used to deploy and manage enterprise virtual environments.


These vulnerabilities exist in VMware products due to improper input validation, insufficient validation of user-supplied input, authorization issues, and other implementation flaws in various product components.


Successful exploitation of these vulnerabilities could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, cause denial of service, and compromise the confidentiality, integrity, and availability of the affected systems.


Solution


Apply the appropriate security updates as recommended by the vendor.

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017



Vendor Information


Broadcom (VMware)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017


References


 

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017


CVE Name

CVE-2025-41225

CVE-2025-41226

CVE-2025-41227

CVE-2025-41228




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzQwkACgkQ3jCgcSdc

ys8++w//WVaG0uHbT8lKGhP63Mo4Y0dluZVBvocZJZPfzc/ThSa10lqcfeauy7+o

KhWvWEAUwMjXpW+02DsyOxzjGHIwKWeLLCOybfNSlzVgl2w+SBZAgGH8xmVh8W/z

e6G/BozQpEVF/0YAazNF613IGFQ9I9DbDNz1x52x5yIlZAdQN02rdkDxPvP9969n

ncnPjx/eKGiVs2Ux52Hp53h/58J7i/Ob1xF/FH/JeB7oYfzXhopQE1CWIW322RBL

MByMqeoLhbsQaDGwRJbxf6NeDpakN0BmIJ1r5G8Z9TNdx8Uzz1lzvwDsfA41BiZp

Vf6+kqHZ7qxxdhUXpQJVzkKZqew+yqRPvCWxum5gaqiGA96wBNzc34sBr1+UkIlA

CFgYcdKK/4mHlP7H9wnsnG8GeJipZWPjxs+G+kaWxKzBnW8nLvA6B/vyYJEcS12v

sY5l59rgW7GAListpGasRl5xzA+MdSOB7u+pXlkEBueb5FhTVKT7I7/mBneUgA9X

RyPdQzhNkubuVWWWMOas0cRY1mPoCbDnDNgmCXuuQo1y+ywF0Li8UejFQhSjAJMy

/9xuJS6KAUb9JbgDhJ/wceRfHfcgDPKwo4g+T4MJmfLGIjWeVQb3DYuIDRlJX8Nq

MFsvW/yKus4Df4pIPIWHSrhesn+DhdTFOwewHto4/9Fh29hpZPI=

=tb4B

—–END PGP SIGNATURE—–

Share this article