VMware vSphere

 View Only
Expand all | Collapse all

How can I download critical security patches without a support contract

  • 1.  How can I download critical security patches without a support contract

    Posted 27 days ago

    Hello,

    I do a lot of work with Cisco collaborations systems that run on Cisco UCS servers and use VMware ESXi to host virtual machines.

    Most of these system were bought as a hardware, hypervisor and software bundle and included a perpetual license for ESXi 7.0 Foundation. Pre-Broadcom Cisco had an arrangement with VMware to provide patches as part of the Cisco support contract.

    This has been cancelled by Broadcom and I now have a number of customers whose systems need patching to address critical vulnerabilities.

    The Broadcom article at the link below says that these patches should be available.

    Zero Day (i.e., Critical) Security Patches for vSphere (7.x and 8.x) Perpetual License Customers with Expired Support Contracts

    Broadcom remove preview
    Zero Day (i.e., Critical) Security Patches for vSphere (7.x and 8.x) Perpetual License Customers with Expired Support Contracts
    that all customers, including those with expired support contracts, will have access to all patches for Critical Severity Security Alerts for supported versions of VMware vSphere. Supported versions of VMware vSphere are versions 7.x and 8.x.
    View this on Broadcom >

    My problem is that I cannot work out how I can access the patch I need (VMware-ESXi-7.0U3w-24784741-depot.zip).

    When I login to the VMware portal I cannot see the download as available.

    Is there a way that I can request access to it?

    Thanks for reading!

    James



  • 2.  RE: How can I download critical security patches without a support contract

    Posted 26 days ago

    i'm sorry that Avango only know making money.




  • 3.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    I don't know if Broadcom makes the critical updates generally available in the support portal or only if there is a matching (expired) perpetual license associated with the account...

    Have you tried to first log in to the support portal then open the release notes for the ESXi-7.0U3w patch (https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/release-notes/esxi-update-and-patch-release-notes/vsphere-esxi-70u3w-release-notes.html) and then follow the direkt link to "this patch" in the "Patch Download and Installation section"?

    Regards,

      Carl




  • 4.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    I believe you can download patches with an expired contract as long as you have perpetual licenses for versions 7.x or 8.x.
    You'll also need a registered account and most likely a Site ID or token.
    That said, you can try what Carl mentioned, sometimes I just go straight to the patch download link from the release notes instead of going through the whole support portal.




  • 5.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    Thanks Carl and Alexandru for replying.

    I have tried accessing the release notes as suggested but the download link was not active.

    As the software was supplied through Cisco I do not believe that there were direct support contracts with VMware.

    I am going to ask Cisco support about this.

    Thanks again for your help.




  • 6.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    I struggled with the same, and found that I can go to the free downloads section to get the patches (even thow the latest is not there?) for our perpetual license. But I have the site id and licenses linked to the account. So not sure if thats needed. ProductDownloads - Support Portal - Broadcom support portal




  • 7.  RE: How can I download critical security patches without a support contract

    Posted 21 days ago

    Hi @James Hawkings, just wanted to follow up on your situation. Did you get any help or updates from Cisco?
    Have you also considered opening a case with Broadcom to get their official stance on the zero-day vulnerabilities for customers with perpetual licenses?




  • 8.  RE: How can I download critical security patches without a support contract

    Posted 21 days ago

    Hi, I raised a case with Cisco TAC and was immediately told that they were unable to help. I asked for my query to be passed to the product management team for the BE6000 product which the licenses were bundled with and that was refused too.

    I was told to contact my Cisco account manager but we no longer have one after Cisco's staff cull last year. There will be hundreds of other Cisco customers with the same issue so I am far from impressed.




  • 9.  RE: How can I download critical security patches without a support contract

    Posted 21 days ago

    Honestly, might be worth opening a case directly with Broadcom. Even without support, they should give at least a formal reply.
    At minimum, it puts some pressure and creates a bit of noise... especially if more people do the same.




  • 10.  RE: How can I download critical security patches without a support contract

    Posted 15 days ago

    I have already tried support tickets, however, without satisfying results.

    The Register reported about similar experiences https://www.theregister.com/2025/07/23/vmware_patch_download_problems/ but Broadcom still does not provide a solution.




  • 11.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    They won't give you a token if you have no active VCF/vsphere contracts.  You can register on the portal, but on the My Downloads page you will not see anything but a link to "free downloads".  On that page, go into Solutions tab and you can download ESXi 7.0U3s, but not the latest w.  They do not seem to be making that available.




  • 12.  RE: How can I download critical security patches without a support contract

    Posted 25 days ago

    No, not at all.

    I wanted to share a personal update regarding VMware products. I've been a strong advocate for them in the past, based on their excellent quality and reliability. I even recommended our company invest in their solutions.
    However, since the transition to Broadcom, my experience has drastically changed. It feels as though customer relationships have taken a back seat to revenue, and essential access is now limited unless additional payments are made. I find this approach disappointing and misaligned with the standards I value.
    Unless there are truly no alternatives, I won't be supporting or using their products going forward




  • 13.  RE: How can I download critical security patches without a support contract

    Posted 24 days ago

    Hi,

    I've the very same challenge. I opened a support ticket and was told that holders of perpetual licenses without valid support contact have to wait 90 days until they can download critical security updates. Actually, this is completely unacceptable and contradicts statements from Broadcom CEO. I asked the support agent to escalate this to management, however, I am in doubt that this happened.

    If you have any idea how to escalate this issue and remind Broadcom of their CEO's statement about secure use of perpetual licenses, would be highly appreciated. Contact press might be another option.




  • 14.  RE: How can I download critical security patches without a support contract

    Posted 21 days ago

    Same topic here.  I have perpetual licenses for version 8 hypervisor and vcenter. also i was able to create a download-token. But all downloads , updates etc. for this security update failed because I'm not entitled.  I had some chat with the support and pointed also to the KB article. I got only the answer  that the patch will be available for customer without contract on a later date. The date could not be defined. Then i was forced to renew my contracts to get updates. 




  • 15.  RE: How can I download critical security patches without a support contract

    Posted 21 days ago

    Meanwhile I've shared my experience with The Register (https://www.theregister.com/2024/04/16/broadcom_vmware_perpetual_license_support/). They will ask Broadcom for a statement. Let's see…




  • 16.  RE: How can I download critical security patches without a support contract

    Posted 12 days ago

    Im having this arguement with broadcom as we speak.  They told me this:  "our support portal requires validation of customer entitlements for software patches, only entitled customers have access to the patches at this time. A separate patch delivery cycle will be available for non-entitled customers and will follow at a later date."

    I asked where in the public domain does it say they and i was told it isnt. It's on their internal systems.  I repeatedly sent them the link https://knowledge.broadcom.com/external/article/314603/zero-day-ie-critical-security-patches-fo.html stating that we're a customer with a perpetual license, support expired 2 weeks ago but we want to install the latest patch for v7 (w) as is addresses several cvss 9.3 critical issues.   Going in circles, managed to get a ticket open, to which they instantly closed parroting the above.  I've asked for it to be kept open and to escalate.

    -------------------------------------------



  • 17.  RE: How can I download critical security patches without a support contract

    Posted 11 days ago

    I'm in the same boat.  I've been tearing my hair out for hours trying to figure this out before I came across this thread. 

    The idea that critical security patches would be intentionally withheld is absolutely absurd to me.

    -------------------------------------------