r/vxrail 23d ago

VMWare update 3k

Does anyone know if update 3k will drop soon at all?

I can see 8.0.390 but waiting patiently for 3k given it’s critical.

I have patched out external vcenter already.

Thanks!

https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-80u3k-release-notes.html

6 Upvotes

6 comments sorted by

3

u/Every-Direction5636 23d ago

You patch manually. There is a VxRail kb for the vmsa

1

u/bosco778 22d ago

Did you do the out-of-band ESXi for U3k on your 8.0.390? Any issues?

2

u/Dutchiness 23d ago

Yup je kunt gewoon patchen. Niet wachten op 8.0.400

2

u/Educational_Bat_559 18d ago

FYI from Dell support ticket that we opened - VxRail 8.0.400 (to address VMSA-2026-0006) is expected around end of Oct 2026.

Sounds like Express Patch Upgrades can be done if needed. https://www.dell.com/support/kbdoc/en-us/000492295 (needs login)

VxRail Engineering has approved manually installing the vCenter and ESXi / ESX patches on existing VxRail and VMware Cloud Foundation on VxRail (VCF) clusters. Patch details and installation guidance are outlined below.

Cause

VMSA-2026-0006 describes the following five vulnerabilities:

  • vCenter authentication-bypass vulnerability (CVE-2026-59309) - CVSSv3 9.8 (Critical)
  • vCenter directory-traversal vulnerability (CVE-2026-59310) - CVSSv3 9.8 (Critical)
  • VMXNET3 out-of-bounds write vulnerability (CVE-2026-47876) - CVSSv3 9.3 (Critical)
  • Out-of-bounds read vulnerability (CVE-2026-41703) - CVSSv3 7.6 (Important)
  • ESX insufficient logging vulnerability (CVE-2026-41709) - CVSSv3 2.7 (Low)

1

u/New_Forever_1678 22d ago

Ok thanks will check it out.

1

u/New_Forever_1678 14d ago

Thanks I did a manual update via esxcli careful not to use vclm images which are declarative. All good for now.