FR
live
High CVSS 7.6

CVE-2026-41703

NVD analysis in progress

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

What this means

Exposure
Exploitable remotely over the network, with a privileged account and with no action from the victim.
Impact
An attacker can read sensitive data and degrade the service. The impact spreads beyond the vulnerable component into other parts of the system.
Weakness
An out-of-bounds read exposes adjacent memory, often leftover secrets.
Likelihood
Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
30 July 2026
CVSS
7.6 (v3.1) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
EPSS
0.63% probability of exploitation within 30 days · above 48% of all CVEs
Weakness
CWE-125
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss