CVE-2026-41703

Summary

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Affected Software

VendorProductVersion RangeStatus
VMwareCloud Foundation9.1.x.xaffected
VMwareCloud Foundation9.0.x.xaffected
VMwareCloud Foundation5.x < 5.2.3affected
VMwarevSphere Foundation9.1.x.xaffected
VMwarevSphere Foundation9.0.x.xaffected
VMwareESX9.1.x.x < ESXi-9.1.0.0-25370933affected
VMwareESX9.0.x.x < ESXi-9.0.2.0100-25595025affected
VMwareESX8.0 < ESXi80U3i-25205845affected
VMwareWorkstation25H2 < 26H1affected
VMwareFusion25H2 < 26H1affected
VMwareTelco Cloud Platform5.1.xaffected
VMwareTelco Cloud Platform5.0.xaffected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds read

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References