CVE-2026-41703

high VMware
CVSS v3 Base Score
7.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Confidentiality
High
Integrity
None
Availability
Low
Published: July 30, 2026 (38 days ago)
Last Modified: July 30, 2026
Vendor: VMware
Source: MITRE

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

CWE

CWE-125

Affected Products

VMware Cloud FoundationVMware vSphere FoundationVMware ESXVMware WorkstationVMware FusionVMware Telco Cloud Platform

References