VMSA-2026-0006 on the 9.1 Stream One vCenter Quick Patch and You’re Done

The same 29 July advisory that patched three components on 9.0.2 asks exactly one thing of VCF and VVF 9.1 estates: vCenter 9.1.0.0300, resolving CVE-2026-59310.

Share

Alongside the 9.0.2.0100 security wave I covered in the previous post, Broadcom released an Express Patch for the 9.1 stream on 29 July 2026: VMware vCenter 9.1.0.0300, for both VMware Cloud Foundation 9.1.0.0 and VMware vSphere Foundation 9.1.0.0, resolving CVE-2026-59310 under security advisory VMSA-2026-0006.

That’s the whole manifest for this stream: one component, one CVE. As always, read the advisory itself for severity and applicability against your deployment VMSA-2026-0006 is the authoritative source covering both streams, and version-by-version applicability belongs to the advisory, not to commentary.

The Operation

vCenter 9.1.0.0300 is a Quick Patch–class update. In practice: a targeted, sub-five-minute operation through the standard workflow, with vCenter API consumers provisioning automation, Kubernetes operations, CI/CD pipelines continuing to run through it. For estates that adopted the 9.1 lifecycle model, the realistic gap between reading this advisory and closing it is measured in hours, most of which is change-record paperwork rather than technical work.

Note the version landing point: this brings vCenter to 9.1.0.0300, joining the management components (SDDC Manager, lifecycle services, VCF Operations, License Server, Cloud Proxy) that reached 9.1.0.0300 in the earlier Express Patch wave. If you applied that wave, your fleet target state simply extends by one component; the release notes linked from the advisory carry the sequencing detail.

The Quiet Argument for Staying Current

Put the two 29 July posts side by side and a pattern is visible: the 9.0.2 stream’s action from this advisory spans three components; the 9.1 stream’s action is one vCenter patch. I won’t speculate on the per-CVE applicability reasoning that’s the advisory’s job but the operational observation stands on its own: estates on the current release stream tend to face smaller advisory-day workloads, applied through faster mechanisms. Currency compounds. The estates that treat “stay current” as an operating principle rather than an annual project keep finding that advisory days are quiet days.

What to Do Today

• Read VMSA-2026-0006 against your 9.1 deployment.

• Apply vCenter 9.1.0.0300 via Quick Patch through your standard workflow prechecks first.

• Update your fleet target state to reflect vCenter at 9.1.0.0300 alongside the earlier management-component wave.

• Time the advisory-to-remediated gap same metric as the 9.0.2 piece. On this stream it should be your shortest on record; that number is worth keeping.

Broadcom VMware Security Advisories portal (VMSA-2026-0006)

Broadcom TechDocs VCF 9.1 Release Notes hub (patch releases 9.1.0.x)

VCF 9.1.0.0 Download Page

VVF 9.1.0.0 Download Page

Per-component release notes: VMware vCenter 9.1.0.0300 https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/patch-releases-9-1-0-x/vsphere/vcenter/vcenter-9-1-0-0300-release-notes.html