VMware vSphere 8.0 Update 3k 发布 - 企业级工作负载平台
VMware vSphere 8.0 Update 3k 下载 - 企业级工作负载平台
vSphere 8.0U3 | ESXi 8.0U3 & vCenter Server 8.0U3
请访问原文链接:https://sysin.org/blog/vmware-vsphere-8-u3/ 查看最新版。原创作品,转载请保留出处。
作者主页:sysin.org
2026-07-29,vSphere 8.0U3k 发布,本站 (sysin) 同步更新。
摘要:VMware 发布 vSphere 8.0 Update 3k 安全补丁,彻底修复 ESXi 虚拟机越界写入(CVSS 9.3)及 vCenter 身份验证绕过与远程代码执行(CVSS 9.8)等多项高危安全隐患。
企业级工作负载平台
vSphere
获得企业级工作负载平台的强大功能。提高工作负载性能、提高安全性并加快业务创新。

新增功能
关于此版本的通用新功能描述请参看:VMware vSphere 8 Update 3 新增功能
ESXi 8.0U3k 安全更新
ESXi 8.0U3k 为安全更新:解决了 CVE-2026-47876。漏洞描述如下。
VMXNET3 越界写入漏洞(CVE-2026-47876)
描述:VMware ESX 的 VMXNET3 虚拟网络适配器中存在一个越界写入漏洞。博通(Broadcom)经评估认为此问题的严重程度属于严重级别(Critical),最高 CVSSv3 基础分数为 9.3。
已知攻击途径:在配置有 VMXNET3 虚拟网络适配器的虚拟机上,拥有本地管理员权限的恶意攻击者可以利用此问题在主机上执行代码。非 VMXNET3 虚拟适配器不受此问题影响。
解决方案:要修复 CVE-2026-47876,请安装下方“响应矩阵(Response Matrix)”中“修补版本(Fixed Version)”一栏所列出的补丁。
变通办法:无
附加文档:已创建补充 FAQ 以作澄清说明。请参阅:https://brcm.tech/vmsa-2026-0006
致谢:博通感谢 STARLabs SG 的 Nguyen Hoang Thach (@hi_im_d4rkn3ss) 配合 Zero Day Initiative 举办的 Pwn2Own 竞赛,向我们报告了此问题。
备注:无。
以下为英文原文内容。
VMXNET3 out-of-bounds write vulnerability (CVE-2026-47876)
Description: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.
Known Attack Vectors: A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Resolution: To remediate CVE-2026-47876 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds: None
Additional Documentation: A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments: Broadcom would like to thank Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG working with the Pwn2Own held by Zero day initiative for reporting this issue to us.
Notes: None.
vCenter Server 8.0U3k 安全更新
vCenter Server 8.0U3k 此版本为安全更新:解决了 CVE-2026-59309 和 CVE-2026-59310。漏洞描述如下。
a. vCenter 身份验证绕过漏洞(CVE-2026-59309)
描述:VMware vCenter 的 VMware 目录服务(VMware Directory Service)中存在一个身份验证绕过漏洞。博通(Broadcom)经评估认为此问题的严重程度属于严重级别(Critical),最高 CVSSv3 基础分数为 9.8。
已知攻击途径:拥有 vCenter 网络访问权限的恶意攻击者可以利用此问题绕过身份验证,并获取系统的未授权访问权限。
解决方案:要修复 CVE-2026-59309,请安装下方“响应矩阵(Response Matrix)”中“修补版本(Fixed Version)”一栏所列出的补丁。
变通办法:无
附加文档:已创建补充 FAQ 以作澄清说明。请参阅:https://brcm.tech/vmsa-2026-0006
致谢:博通感谢 Atredis Partners 的 Phil Brass 和 Matt South 向我们报告此问题。
备注:请注意,补丁具有累积性,这意味着当前版本包含了之前发布的所有修复程序。虽然 CVE-2026-59309 最初是在 9.1.0.0200 版本中解决的,但 9.1.0.0300 是目前可用的最新版本,其中同样包含了针对此 CVE 的修复。
b. vCenter 目录遍历漏洞(CVE-2026-59310)
描述:VMware vCenter 的 Syslog 服务器中存在一个目录遍历漏洞。博通(Broadcom)经评估认为此问题的严重程度属于严重级别(Critical),最高 CVSSv3 基础分数为 9.8。
已知攻击途径:拥有 vCenter 网络访问权限的恶意攻击者可以利用此问题执行任意代码。
解决方案:要修复 CVE-2026-59310,请安装下方“响应矩阵(Response Matrix)”中“修补版本(Fixed Version)”一栏所列出的补丁。
变通办法:无
附加文档:已创建补充 FAQ 以作澄清说明。请参阅:https://brcm.tech/vmsa-2026-0006
致谢:博通感谢 Atredis Partners 的 Phil Brass 和 Matt South 向我们报告此问题。
备注:无。
以下为英文原文内容。
a. vCenter authentication-bypass vulnerability (CVE-2026-59309)
Description: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Known Attack Vectors: A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Resolution: To remediate CVE-2026-59309 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds: None
Additional Documentation: A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments: Broadcom would like to thank Phil Brass and Matt South of Atredis Partners for reporting this issue to us.
Notes:Please note that patches are cumulative, meaning the current version includes all previously released fixes. While CVE-2026-59309 was addressed in 9.1.0.0200 first, version 9.1.0.0300 is the most recent version currently available which includes the fix for this CVE.
b. vCenter directory-traversal vulnerability (CVE-2026-59310)
Description: VMware vCenter contains a directory traversal vulnerability in the Syslog server. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
Known Attack Vectors: A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Resolution: To remediate CVE-2026-59310 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds: None
Additional Documentation: A supplemental FAQ was created for clarification. Please see: https://brcm.tech/vmsa-2026-0006
Acknowledgments: Broadcom would like to thank Phil Brass and Matt South of Atredis Partners for reporting this issue to us.
Notes: None.
适用于传统和下一代应用程序的企业级工作负载平台
产品优势

-
提高运营效率
提高 IT 生产力并降低运营费用。

-
提高工作负载性能
为更大的 AI 工作负载提供支持并优化 GPU 资源的性能。

-
加速 DevOps 创新
通过 DevOps 服务实现虚拟机和容器的自助配置。
vSphere 新功能

-
生命周期管理
使用 vSphere 配置文件轻松管理集群级别的主机配置。轻松检测并解决 vCenter 实例的配置偏差。

-
Tanzu Kubernetes Grid 集成
直接在 vSphere 上运行 Tanzu Kubernetes Grid 服务,以简化 Kubernetes 的本地操作。

-
减少升级的计划停机时间
以最小的中断升级 vCenter 实例。

-
提高大型 AI/ML 工作负载性能
通过支持每个虚拟机最多 16 个 vGPU、每个虚拟机 32 个直通设备以及 NVLink 和 NVSwitch 技术的部署,增强大型 AI/ML 工作负载的性能。

-
最大化 GPU 资源的投资回报率
通过 GPU 感知的工作负载放置和负载平衡 (sysin),在不同工作负载之间更有效地共享 GPU 资源。

-
vSphere 绿色指标
跟踪主机和虚拟机级别的功耗。发现优化消费的机会并为组织的可持续发展目标做出贡献。

-
改善基础设施健康状况
最大限度地提高可见性,以保持工作负载的最佳性能。

-
DevOps 自助服务
为 DevOps 和开发团队提供对基础设施资源的自助访问 (sysin),以加快上市速度。

-
运行现代应用程序
在统一平台上使用容器和虚拟机构建和运行现代应用程序以简化管理。
下载地址
The VMware vSphere architecture consists of the following components:
- A base hypervisor, vSphere ESXi Installable, that is installed on every physical server planned for hosting virtual machines
- One instance of a management server called VMware vCenter Server that enables centralized management of multiple vSphere hosts.
VMware vSphere Hypervisor (ESXi) 8.0U3k
下载地址:https://sysin.org/blog/vmware-vsphere-8-u3/
-
发布日期:2026-07-29
-
安全更新:解决了 CVE-2026-47876。详见官方文档及本站相关发布。
-
VMware vSphere Hypervisor (ESXi ISO) image
File Name: VMware-ESXi-8.0U3k-25595708.x86_64.iso -
VMware vSphere Hypervisor (ESXi) Offline Bundle
File Name: VMware-ESXi-8.0U3k-25595708-depot.zip
OEM Custom Image:
- Dell Custom Image for ESXi 8.0U3k Install CD
- HPE ProLiant Custom Image for ESXi 8.0U3k Install CD
- HPE Synergy Custom Image for ESXi 8.0U3k Install CD
- HPE Superdome Flex and Compute Scale-up Server family Custom Image for ESXi 8.0U3k Install CD
- IEIT SYSTEMS Custom Image for ESXi 8.0U3k Install CD
- Lenovo Custom Image for ESXi 8.0U3k Install CD
- H3C Custom Image for ESXi 8.0U3k Install CD
- Cisco Custom Image for ESXi 8.0U3k Install CD
- Fujitsu Custom Image for ESXi 8.0U3k Install CD
- Hitachi Custom Image for 8.0U3k Install CD
- NEC Custom Image for VMware ESXi 8.0U3k Install CD
- Huawei Custom Image for VMware ESXi 8.0U3k Install CD
- xFusion Custom Image for VMware ESXi 8.0U3k Install CD
- 请访问:VMware ESXi 8.0U3k macOS Unlocker & OEM BIOS 2.7 标准版和厂商定制版
VMware vCenter Server 8.0U3k
下载地址:https://sysin.org/blog/vmware-vsphere-8-u3/
-
发布日期:2026-07-29
-
安全更新:解决了 CVE-2026-59309 和 CVE-2026-59310。详见官方文档及本站相关发布。
-
VMware vCenter Server Appliance
File Name: VMware-VCSA-all-8.0.3-25600417.iso
File Size: 11.93 GB -
VMware vCenter Server Appliance Patch
File Name: VMware-vCenter-Server-Appliance-8.0.3.01000-25600417-patch-FP.iso
File Size: 7.95 GB -
VMware vCenter Server Appliance Update Bundle
File Name: VMware-vCenter-Server-Appliance-8.0.3.00900-25413364-updaterepo.zip
File Size: 8.19 GB
本站定制映像:
- VMware ESXi 8.0U3k macOS Unlocker & OEM BIOS 2.7 标准版和厂商定制版
- VMware ESXi 8.0U3k macOS Unlocker & OEM BIOS 2.7 集成网卡驱动和 NVMe 驱动 (集成驱动版)
相关产品:

VMware 发布 vSphere 8.0 Update 3k 安全补丁,彻底修复 ESXi 虚拟机越界写入(CVSS 9.3)及 vCenter 身份验证绕过与远程代码执行(CVSS 9.8)等多项高危安全隐患。
浙公网安备 33010602011771号