Loading...
Loading...
All HPE ProLiant Compute systems configured as part of the HPE Private Cloud Business Edition products may include VMware ESXi versions (VMware ESXi 9.1.x.x; 9.0.x.x & 8.0 U3k/U3j/U2f Patches) which are affected by multiple vulnerabilities as reported by Broadcom as VMSA-2026-0006.1
HPE Private Cloud Business Edition (PCBE) with HPE Alletra dHCI 5000 / 6000HPE Private Cloud Business Edition (PCBE) with HPE Nimble Storage dHCI
Recommendation:Once updated HPE Private Cloud Business Edition with HPE Alletra/Nimble Storage dHCI catalogs are released, leverage the native HPE Private Cloud Business Edition single click update capabilities to receive updated VMware packaging.If immediate remediation is necessary:Therecommended methodsare to:usevLCM baselines (the traditional VUM workflow); ormanually update hosts usingesxcliBroadcom KB 385796 - Upgrading ESXi to 8.x using the vCenter built-in LCM (VUM)HPE Support does not recommend using the vLCM image-based management method for this remediation.This method changes the host profile image and vendor details to "VMware".It is not possible to revert cluster to legacy vLCM method once new method is used.This results in a failed "HPEImageRule" System Health Check.Important Notes & TerminologyIn vSphere 7 and 8, the functionality formerly calledvSphere Update Manager (VUM)is part ofvSphere Lifecycle Manager (vLCM).There are two vLCM management methods:Baselines:The traditional VUM workflow.Images:The newer desired-state workflow recommended by Broadcom.Baseline management is deprecated but remains available in vSphere 8. In vSphere 9, VUM baseline-based lifecycle management is not supported for ESXi 9.x hosts.Once a cluster or standalone host is converted to image-based management, it cannot be directly reverted to baseline management, and the Baselines option is no longer available.Reference:Broadcom KB 322186 - Managing ESXi host lifecycle operations with vLCMReferences:https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017https://nvd.nist.gov/vuln/detail/CVE-2026-59309https://nvd.nist.gov/vuln/detail/CVE-2026-59310https://nvd.nist.gov/vuln/detail/CVE-2026-47876https://nvd.nist.gov/vuln/detail/CVE-2026-41703https://nvd.nist.gov/vuln/detail/CVE-2026-41709Contact Details:For further questions or problems, please use:InfoSight > HPE Alletra 6000, Alletra 5000, Nimble Storage > Resources > SupportPhone: HPE Services – Hybrid Cloud SupportTrademark NoticeVMware, VMware ESXi, and VMware vSphere are registered trademarks or trademarks of Broadcom Inc. and/or its subsidiaries. All other product names may be trademarks of their respective companies.
Operating Systems Affected:VMware ESXi 8.0, VMware ESXi 9.0, VMware ESXi 9.1
Click on a version to see all relevant bugs
Hewlett Packard Enterprise Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.