Original Message:
Sent: Aug 13, 2026 01:33 PM
From: Derek Kirk
Subject: How can I download critical security patches without a support contract
CVE-2026-59310 is under active exploitation and the patch to fix this vulnerability is still not available to perpetual license holders without a support contract.
Beyond ridiculous from Broadcom.
Original Message:
Sent: Aug 12, 2026 04:29 AM
From: LordLeonidas
Subject: How can I download critical security patches without a support contract
Site ID has been there since I got the license way back when...
Within my vCenter portal itself I can see the patching but can't download it / provision the ESXi nodes nor update the vCenter Appliance
And like I wrote earlier the downloads itself (*.zip or ISO for that matter) are nowhere to be found in my Broadcom support portal.
Referring to the following:
- VMware-VCSA-all-8.0.3-25600417.iso
- VMware-vCenter-Server-Appliance-8.0.3.01000-25600417-updaterepo.zip
- VMware-vCenter-Server-Appliance-8.0.3.01000-25600417-patch-FP.iso
Same for the ESXi nodes ofcourse.
Original Message:
Sent: Aug 12, 2026 12:59 AM
From: Nathan Watts
Subject: How can I download critical security patches without a support contract
Do you have a site ID attached to your account?
Original Message:
Sent: Aug 11, 2026 12:07 AM
From: LordLeonidas
Subject: How can I download critical security patches without a support contract
Same here. No patch made available in my portal.
However, if one can have critical patching occurring within the 90 days delay period you basically can "flip the finger" to non-paying or ex-customers till kingdom comes.
Of course, a 90 days delay for a critical patch is in my opinion Broadcom's way of forcing you to upgrade or leave yourself unprotected, but I am guessing that is not Broadcom's concern. The mighty dollar is.
Broadcom is more than free to help me adjust my view of the current state of affairs but since I have been in chats with Broadcom I got answers by them to have a look at the portal for downloads this and that and of course the "cow droppings" reply of the 90 days delay.
Not holding my breath and neither should you.
Original Message:
Sent: Aug 06, 2026 03:10 AM
From: Nathan Watts
Subject: How can I download critical security patches without a support contract
This has not been my experience, but all things being equal, they most likely are not equal :)
I'll need to ask.
Original Message:
Sent: Aug 06, 2026 02:45 AM
From: Martin33
Subject: How can I download critical security patches without a support contract
Nathan,
Thank you for sharing the article.
I am aware of this statement from Broadcom, however, reality has proven that the previous patch for a critical vulnerability was available on customer support portal only after 90 days. While this very bad practice, it seems that Broadcom still applies this policy.
Can you confirm this?
Or can you provide us with better news?
Original Message:
Sent: Aug 06, 2026 12:44 AM
From: Nathan Watts
Subject: How can I download critical security patches without a support contract
This is the article you are referring to, it has the details in there.
Article 314603
To access the updates:
Customers can continue to apply patches through existing product patching mechanisms, including the VMware Support Portal, and after May 6, 2024, by registering or using their existing registration for support.broadcom.com.
Original Message:
Sent: Aug 05, 2026 12:33 PM
From: Martin33
Subject: How can I download critical security patches without a support contract
Apparently, things start over for VMSA-2026-0006.
Same situation: Patch ESXi-8.0U3k has been published but is not (yet) available for download. I assume the "90 days delay policy" is still in place.
Has anyone heard any news from Broadcom support or others whether there was (or should have been) any change in this respect?
Thanks!
Original Message:
Sent: Oct 23, 2025 05:46 AM
From: Matthew Wilson
Subject: How can I download critical security patches without a support contract
Excellent, I had given up. Thanks for alerting us.