Description
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
Published: 2026-07-30
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an out‑of‑bounds read within VMware ESX, Workstation, and Fusion. An attacker who can deploy virtual machines can trigger the flaw, causing the host to read memory beyond a buffer’s boundary. This can expose sensitive host information and more typically destabilise the host process, resulting in a denial‑of‑service. The weakness is identified as CWE‑125.

Affected Systems

Affected VMware products include Cloud Foundation, vSphere Foundation, ESX, Telco Cloud Platform, Workstation, and Fusion. No specific version list is provided, so any un‑patched installation of these products remains vulnerable.

Risk and Exploitability

The CVSS score of 7.6 classifies the vulnerability as high severity. The EPSS score of 0.00556 (<1%) and the fact that it is not listed in the CISA KEV catalog indicate that widespread exploitation is currently unlikely, though the probability is non‑zero. Attackers require virtual‑machine deployment privileges, limiting the threat to users with elevated configuration rights. Until an official fix is deployed, the risk to hosts with open deployment permissions remains moderate to high.

Generated by OpenCVE AI on August 2, 2026 at 05:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest VMware security patch for Cloud Foundation, vSphere Foundation, ESX, Telco Cloud Platform, Workstation, and Fusion.
  • Restrict VM deployment privileges to the minimum necessary operators and audit any changes to these permissions.
  • Monitor host processes for abnormal crashes or memory reads and configure alerts to detect repeated failures indicative of an exploit attempt.

Generated by OpenCVE AI on August 2, 2026 at 05:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware esx
Vmware fusion
Vmware telco Cloud Platform
Vmware vsphere Foundation
Vmware workstation
Vendors & Products Vmware
Vmware cloud Foundation
Vmware esx
Vmware fusion
Vmware telco Cloud Platform
Vmware vsphere Foundation
Vmware workstation

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
Title Out-of-bounds read vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Vmware Cloud Foundation Esx Fusion Telco Cloud Platform Vsphere Foundation Workstation
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T15:09:25.467Z

Reserved: 2026-04-22T06:21:22.982Z

Link: CVE-2026-41703

cve-icon Vulnrichment

Updated: 2026-07-30T15:08:43.618Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T13:16:49.300

Modified: 2026-07-30T16:17:11.403

Link: CVE-2026-41703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses