CVE-2026-41709 Details
Description
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
A vulnerability exists in VMware ESX due to inadequate logging. This issue allows a malicious administrator to carry out certain actions without them being recorded. The vulnerability affects VMware ESX versions 9.1.x.x, 9.0.x.x, and 8.0, as well as VMware Cloud Foundation 5.x and Telco Cloud Platform versions 5.0.x and 5.1.x.
Users can upgrade to VMware ESX 9.1.0.0-25370933, 9.0.2.0100-25595025, or 8.0 U3j. VMware Cloud Foundation users can upgrade to version 5.2.4. VMware Telco Cloud Platform users can refer to knowledge base article KB449886 for guidance.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-778 | Insufficient Logging | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |