CVE-2026-41703
published 2026-07-30CVE-2026-41703: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds…
PriorityP342high7.6CVSS 3.1
AVNACLPRHUINSCCHINAL
EPSS
0.56%
43.9th percentile
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | >= 5.x < 5.2.3 | 5.2.3 |
| vmware | esx | >= 8.0 < ESXi80U3i-25205845 | ESXi80U3i-25205845 |
| vmware | esx | >= 9.0.x.x < ESXi-9.0.2.0100-25595025 | ESXi-9.0.2.0100-25595025 |
| vmware | esx | >= 9.1.x.x < ESXi-9.1.0.0-25370933 | ESXi-9.1.0.0-25370933 |
| vmware | fusion | >= 25H2 < 26H1 | 26H1 |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | vsphere_foundation | — | — |
| vmware | vsphere_foundation | — | — |
| vmware | workstation | >= 25H2 < 26H1 | 26H1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2026-07-30
Published