VMSA-2026-0006 for the vSphere 8 Estate ESXi and vCenter 8.0 U3k, and the Live-Patch Catch

The 29 July advisory reaches vSphere 8: ESXi 8.0 U3k resolves CVE-2026-47876 live-patchable and vCenter 8.0 U3k closes two more.

Share

Completing the 29 July 2026 security wave: Broadcom released Express Patches for the vSphere 8 stream under the same advisory, VMSA-2026-0006, that patched VCF/VVF 9.0.2 and 9.1 the same day. For the majority of estates which is to say, the ones still running vSphere 8 this is the release that matters.

What Shipped

• ESXi 8.0 Update 3k resolves CVE-2026-47876. This release is live-patchable: eligible hosts take it in memory, no reboot, no evacuation.

• vCenter 8.0 Update 3k resolves CVE-2026-59309 and CVE-2026-59310.

As with the companion posts: severity, exploitability, and per-version applicability are documented in VMSA-2026-0006. Read the advisory against your estate it is the authoritative source across all three streams patched on the 29th, and the manifest differences between streams belong to the advisory’s applicability analysis, not to commentary.

The Live-Patch Catch and Why It Matters Today

Here’s the operational detail that decides whether “live-patchable” applies to you: the ESXi live-patch path on vSphere 8 runs through vSphere Lifecycle Manager images. Clusters still managed with baselines don’t get the in-memory route they take the standard remediation cycle, maintenance mode and all. Check the 8.0 U3k release notes for the full eligibility constraints on your hardware and configuration (and note that on 8.x, TPM-enabled hosts follow the standard path the gap that VCF 9.1’s Live Patch extension closed on the newer stream).

Regular readers will see where this lands. Last week’s piece made the case that the baselines-to-images transition is mandatory before vSphere 9 and worth doing in a quiet quarter. Today sharpened the argument considerably: image-managed clusters can take a CVE fix in memory this week; baseline-managed clusters are scheduling evacuation windows for the same fix. The transition isn’t just upgrade insurance anymore it’s the difference in your remediation speed on advisory day, starting with this advisory.

What to Do Today

• Read VMSA-2026-0006 against your deployment all three CVEs, your versions, your configuration.

• Apply vCenter 8.0 U3k first per your standard sequencing vCenter before hosts, as ever. Check the release notes for interoperability specifics.

• For image-managed clusters: update the image definition to 8.0 U3k, review compliance, remediate eligible hosts take the live-patch path.

• For baseline-managed clusters: remediate through the standard cycle and put the image transition on next quarter’s plan with today as exhibit A.

• Time the advisory-to-remediated gap and if you run both cluster types, time them separately. The delta between your image clusters and baseline clusters on the same advisory is the business case for the transition, measured in your own estate.

The Takeaway

One advisory, three streams, one day and the remediation experience varied entirely by how each estate’s lifecycle model was set up before the advisory landed. 9.1 estates closed it with a single Quick Patch. Image-managed 8.x clusters take the ESXi fix in memory. Baseline-managed clusters are booking windows. Patching speed is decided before the CVE is published that’s the whole lesson of this platform generation, demonstrated in a single Tuesday.

Broadcom VMware Security Advisories portal (VMSA-2026-0006)

Downloads:

ESXi 8.0 U3k https://support.broadcom.com/web/ecx/solutiondetails?patchId=16106

vCenter 8.0 U3k https://support.broadcom.com/web/ecx/solutiondetails?patchId=16109

Release notes:

ESXi 8.0 U3k https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3k-release-notes.html

vCenter 8.0 U3k https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/vcenter-server-update-and-patch-release-notes/vsphere-vcenter-server-80u3k-release-notes.html

Background reading from the Field Guide: the baselines-to-images playbook (Part 56), and the three-layer patching model piece with Broadcom’s non-disruptive security patching whitepaper.