cbcvebase.
CVE-2026-41709
published 2026-07-30

CVE-2026-41709: VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being…

PriorityP410low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.38%
31.5th percentile
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

Affected

10 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation
vmwarecloud_foundation
vmwarecloud_foundation>= 5.x < 5.2.45.2.4
vmwareesx>= 8.0 < ESXi80U3j-25429389ESXi80U3j-25429389
vmwareesx>= 9.0.x.x < ESXi-9.0.2.0100-25595025ESXi-9.0.2.0100-25595025
vmwareesx>= 9.1.x.x < ESXi-9.1.0.0-25370933ESXi-9.1.0.0-25370933
vmwaretelco_cloud_platform
vmwaretelco_cloud_platform
vmwarevsphere_foundation
vmwarevsphere_foundation
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.