September 14, 2026 · Biweekly · Coverage window: 9/1–9/13
From the Editor
Hello, readers — welcome to Issue 002 of Virtualization Watch.
The past two weeks were the densest fourteen days of the quarter for virtualization: VMware Explore 2026 opened in Las Vegas on August 31 and wrapped on September 3, with Broadcom pushing “Private AI Cloud” to the very front of the private-cloud narrative; in the same week, Proxmox announced 24/7 enterprise support and a North American subsidiary back to back, then earned Omnissa Horizon certification — the open-source camp’s commercialization is visibly accelerating. The security side was heavier: a CVSS 9.3 VM-escape vulnerability hit Workstation/Fusion, and Microsoft’s September Patch Tuesday set an all-time record with 974 fixes, five of them in Hyper-V alone.
As AI workloads become the centerpiece of every roadmap, hypervisor competition is shifting from “running VMs” to “running models well on GPUs.” Let’s begin.
In This Issue: VMware Explore 2026 — AI Factory Debuts, vSphere 9.1 Earns NVIDIA Certification
VMware Explore 2026 ran August 31 – September 3 at The Venetian Convention and Expo Center in Las Vegas (VMware event page). Our news window covers every official announcement from the show; the two weightiest are VMware AI Factory and NVIDIA certification for vSphere 9.1 (VMware official blog, September 3, 2026).

Key points:
- VMware AI Factory: positioned as the software-defined foundation of the “VMware Private AI Cloud,” aiming to compress the time from bare-metal servers to a first production AI model “from weeks to hours,” spanning hardware provisioning, software-stack enablement, and full lifecycle management.
- Ecosystem and hardware: works with Dell PowerEdge certified servers and VCF AI ReadyNodes from Cisco, Lenovo, Supermicro, and others; a partnership with AMD delivers zero-touch provisioning of Instinct GPUs with the open ROCm stack; a separate partnership with MetalSoft integrates heterogeneous bare-metal automation directly into the VCF management console.
- Model runtime: vLLM is the default model runtime, with 150+ open models; models officially named as tested on VCF include NVIDIA Nemotron 3, Google Gemma 4, NEC cotomi, Alibaba Qwen3.8-27B, and Zhipu GLM 5.2.
- NVIDIA certification: NVIDIA recently launched the NVIDIA-Certified Hypervisors program, and vSphere 9.1 (and all subsequent vSphere 9 releases) are among the first certified, with official claims of “near bare-metal” performance for AI/HPC workloads on VCF.
- Private AI services ecosystem additions: Appian, ClearML, Eve Security, Solo.io, and TrueFoundry.
Editor’s take: this year’s Explore barely discussed “virtualization” itself — every announcement targeted the private cloud in the Agentic AI era. Broadcom’s logic is straightforward: GPUs are expensive, token costs are spiraling, and data must stay on-premises — all three are the private cloud’s home turf. For enterprise users, what truly needs evaluation is not the AI Factory concept, but whether the GPU supply chain works smoothly after upgrading an existing VCF environment to 9.1.
Product & Version News
VMware Cloud Foundation 9.1.1 Reaches GA (September 3)
Timed with Explore 2026, Broadcom announced the general availability of VCF 9.1.1 (official blog) — the first maintenance release of VCF 9.1 (released in May). Highlights:
- Multi-tenant model sharing: AI models can be securely shared across tenants/business units, while training data and access controls remain tenant-isolated, cutting duplicate deployment costs;
- AI Assistant for VCF: AI-assisted diagnostics (e.g., ESX CPU/memory contention, locating batch vMotion errors) and management-pack building;
- vSAN Object Storage (tech preview) and cumulative security fixes.

Note the upgrade-order constraints: William Lam’s blog post (analysis published September 10) reminds readers that Fleet LCM must be upgraded to 9.1.1 before all other components, VCFMS must go before Identity Broker and Salt Master/RaaS, and VCF Automation before VCD Migrator (the corresponding pre-checks are built into the release).
VMware Workstation / Fusion 26H1u1 (September 3)
The desktop hypervisor line shipped 26H1u1, whose core purpose is fixing the two vulnerabilities in VMSA-2026-0007 (see “Security Advisories”), while also introducing automated Secure Boot platform key (PK) remediation to address the Microsoft Secure Boot certificate expiration (Fusion 26H1u1 release notes, Broadcom TechDocs).
Proxmox: Two Announcements in One Week — 24/7 Support + North America Subsidiary (September 2), Omnissa Certification (September 4)

On September 2, Proxmox Server Solutions announced (official press release):
- Enterprise support expands to 24/7, effective October 19, 2026, covering the PVE, PBS, and PDM product lines; the Premium tier includes 24/7 from day one (unlimited tickets, 2-hour response for critical issues), the Standard tier opens in Q4 2026, and the Basic tier’s SLA is unchanged though the global team’s cross-timezone shifts will shorten real-world response times;
- A new subsidiary, Proxmox North America Inc., headquartered in Kingston, Ontario, Canada, led by CEO Bill Hughes, handling sales, contracts, and business-hours technical support across North American time zones;
- Operating figures disclosed alongside: over 2.3 million active PVE servers worldwide, 60,000+ enterprise customers with paid support, and roughly 3,000 integration partners.
On September 4, Proxmox announced (official press release) that Proxmox VE has officially passed Omnissa Horizon Ready Hypervisor certification: interoperating with Omnissa Horizon in Manual Provisioning Mode, enterprises can centrally deliver virtual desktops and applications on existing PVE infrastructure; PVE also appears on the NVIDIA vGPU support list as a certified third-party hypervisor. Verified configurations are in the Omnissa interoperability matrix.

Editor’s take: from official Arm64 support on August 5, to this issue’s 24/7 support and VDI ecosystem certification, Proxmox’s “catch the spillover” playbook under Broadcom’s licensing squeeze is becoming systematic — first it caught the migrations, then the services, and now even the VDI desktop cloud.
Nutanix Lands in Two Gartner Magic Quadrants in a Fortnight (September 8 / September 10)
Per the Nutanix newsroom (official Newsroom): on September 10, Nutanix was named a Leader in the 2026 Gartner Magic Quadrant for Distributed Hybrid Infrastructure (on both Ability to Execute and Completeness of Vision); on September 8, it appeared for the second consecutive year in the Gartner Magic Quadrant for Container Management (the official blog headline positions it as a “Challenger”).

KubeVirt v1.10.0-alpha.0 Released (September 4)
The KubeVirt community published v1.10.0-alpha.0 on GitHub (release page): about five weeks after v1.9.0 (July 30), this cycle accumulated 824 changes from 72 contributors. Notable changes: the KubevirtSeccompProfile feature gate graduates to GA and is installed by default; ExternalNetResourceInjection graduates to GA, and virt-controller no longer queries NetworkAttachmentDefinition directly; SR-IOV interfaces can no longer be mixed with DRA networking.

Release Footnotes from Outside the Window
- No new VirtualBox release this issue; the latest remains 7.2.16 from August 18 (VirtualBox official News);
- QEMU 11.1 shipped on August 11 (UFS 4.1 emulation, RISC-V big-endian support) — before this window, for reference.
Community Buzz
ZSvirt on Show HN: Lightweight Open-Source Virtualization Platform Draws 72 Points (September 2)
Editor’s disclosure: this newsletter is produced by the ZSvirt team; this item is related-party content and is disclosed as such. All figures below come from live captures of public pages.
On September 2, the open-source virtualization platform ZSvirt appeared on Hacker News’ Show HN: “Show HN: ZSvirt – A lightweight, scalable open source virtualization platform” (original HN post). As of our September 13 capture, it had 72 points and 14 comments.

The comment section’s questions were strikingly focused, outlining the four things the community cares most about in an emerging virtualization platform:
- Performance benchmarks: multiple users asked for benchmarks against Proxmox, standalone KVM, and OpenStack — VM boot time, migration speed, and control-plane overhead;
- VMware migration: the VMDK/OVF compatibility experience, and the networking/storage pitfalls when migrating from vSphere, were asked repeatedly;
- Networking capabilities: how hard VLAN and NAT configuration is compared with Proxmox;
- Lab barrier to entry: the minimum memory for running the OVA image under nested virtualization on a single node, plus the maturity of multi-tenant management and the API ecosystem.

On the repository side (GitHub: ZSvirt/zsvirt): positioned as a “core IaaS engine and cloud infrastructure foundation,” built on KVM, written mainly in Java (78.2%), GPL-3.0 licensed, with 1.7k stars and 306 forks as of our September 13 capture. Ready-made qcow2 and OVA images can be tried via nested virtualization on VMware, VirtualBox, KVM, or cloud hosts, and there is an online demo (demo.zsvirt.io). The repository has no formal release yet — worth tracking.
vphone-cli Heats Up Again: iOS 27 RC in the Catalog, HN Post at 421 Points
The open-source project vphone-cli (which boots a “virtual iPhone” on Apple Silicon Macs using Apple’s Virtualization.framework and the PCC research-VM infrastructure) saw a second wave of attention in this window:
- The Hacker News front-page thread from late August, “Boot a Virtual iPhone via Apple’s Virtualization.framework,” now sits at 421 points and 113 comments (original HN post), with comments still growing inside our window; the community consensus is that “this isn’t Corellium-style emulation — it’s real virtualization,” alongside a warning not to select Japan or the EU region during initialization (the VM cannot pass third-party app-store compliance checks);
- On September 10, a repository commit added the iOS 26.6.2 + iOS 27.0 RC (cloudOS 26.4) pairing, with v1.0.14 released the same day; InfoQ covered the project’s full iOS 27 virtualization support on September 12, driving a fresh round of discussion;
- As of our September 13 capture, the repository had 11.8k stars and 1.5k forks, primarily Swift (58.6%).


The community’s main concerns are worth recording too: Apple does not officially support this usage, and future PCC images may remove necessary components; the host also requires loosening SIP/AMFI security policies — use a dedicated research machine.
Proxmox VE 8 Officially EOL; the Upgrade Wave Continues
Security support for Proxmox VE 8 ended on August 31 (endoflife.date) — one day before this window — and community discussion of the 8-to-9 upgrade kept simmering throughout: the kernel jumps from 6.8 to 7.x, NICs may be renamed, LVM auto-activation defaults change, and PCI passthrough needs re-checking. Readers still on VE 8 can consult VirtualizationHowto’s upgrade checklist — run pve8to9 --full first, pin NIC names, and have out-of-band console access ready.
VMSA-2026-0007 Becomes the Fortnight’s Must-Do for Desktop Virtualization Users
In the VirtualizationHowto community, the VMSA-2026-0007 discussion thread is among the hottest: VMXNET3 is the default virtual NIC for most users, and “first inventory which dev and test machines have Workstation/Fusion installed” became the thread’s consensus — desktop hypervisors are rarely in the enterprise asset inventory, which is exactly what makes this vulnerability tricky in practice.
Security Advisories
[Critical] VMSA-2026-0007: Workstation / Fusion VM Escape (September 3)
Broadcom published VMSA-2026-0007 (VMware Security Blog | Broadcom official advisory), affecting VMware Workstation 25H2/26H1 and Fusion 25H2/26H1 (macOS); ESXi and vCenter are not affected:

| CVE | Component | Type | CVSS v3 | Impact |
|---|---|---|---|---|
| CVE-2026-59346 | VMXNET3 virtual NIC | Integer overflow | 9.3 (Critical) | A local administrator inside the VM can execute code on the host (VM escape) |
| CVE-2026-59347 | HGFS shared folders | Stack buffer overflow | 8.1 (Important) | A local administrator inside the VM can execute code with the identity of the host VMX process |
- Fixed in: 26H1u1 (same version number for Workstation and Fusion); no workarounds — upgrading is the only option;
- Both vulnerabilities were reported privately, and Broadcom is not aware of in-the-wild exploitation; reporters include h4urek of secsys lab, Y² and Stan S via Trend Micro ZDI, and Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab;
- CERT-FR issued a corresponding advisory on September 4;
- A side note: 26H1u1 also introduces automated Secure Boot platform-key remediation — before upgrading, make sure guests have the July 2026-or-later Windows cumulative update installed (in combination with VMware Tools 13.1.5).
Recommended action: users who frequently run third-party images, analyze samples, or execute untrusted workloads on their machines should upgrade first. If you cannot upgrade immediately, disabling HGFS shared folders and tightening in-VM administrator privileges will shrink the attack surface (unofficial mitigation — reduces risk only).
[Largest Ever] Microsoft September Patch Tuesday: 974 Vulnerabilities, Five in Hyper-V (September 8)
Microsoft’s September 2026 Patch Tuesday fixed 974 vulnerabilities (113 Critical, 860 Important), which Qualys calls “Microsoft’s largest security update ever” (Qualys analysis, September 9); two additional vulnerabilities are already being exploited in the wild.

Directly virtualization-relevant: five Hyper-V vulnerabilities (Lansweeper roundup):
- CVE-2026-80083: Hyper-V remote code execution (untrusted pointer dereference), Critical;
- CVE-2026-69603: Hyper-V remote code execution (heap buffer overflow), Critical;
- CVE-2026-69910: Hyper-V remote code execution, Critical;
- CVE-2026-72961: Hyper-V elevation of privilege (out-of-bounds read);
- CVE-2026-69553: Hyper-V elevation of privilege.
Splashtop’s patch-priority analysis (September 9) places Hyper-V, Failover Clustering, and Windows Deployment Services in the “patch within 72 hours” tier — once a host is compromised, every guest workload on it is exposed. A VHD Miniport driver denial-of-service flaw (CVE-2026-69384) was fixed alongside; include it in your host patching window.
Tools & Good Reads
- vphone-cli (GitHub, MIT license): a single command runs the whole pipeline — download firmware → patch → DFU restore → install the customized firmware → first boot — with SSH/VNC access and five security-bypass variants (from patchless to full jailbreak); the companion vphone-mcp wraps the control socket as an MCP service, letting AI agents take screenshots, drive touch input, and automate UI testing. Once again: SIP/AMFI must be loosened — dedicated research machines only.
- “10 Exciting Enhancements in VMware Cloud Foundation 9.1.1” (William Lam, September 10): ten detailed enhancements in VCF 9.1.1 plus upgrade-order caveats, written on-site at Explore by a Broadcom frontline engineer.
- “Still Running Proxmox VE 8?” (VirtualizationHowto, August 19): the pre-EOL upgrade checklist and version support matrix — read together with this issue’s “Community Buzz.”
- “Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review” (Qualys, September 9): a panoramic breakdown of the 974 vulnerabilities with tiered patching advice.
- Broadcom TechDocs: Workstation / Fusion 26H1u1 release notes (link): official details on the CVE fixes and Secure Boot PK remediation.
Number of the Week: 974
The total number of vulnerabilities fixed in Microsoft’s September 2026 Patch Tuesday — 113 Critical, 860 Important, plus two zero-days exploited in the wild. Qualys confirms it is Microsoft’s largest single-month security update ever (July had 570, August 400). Six are virtualization-related: five in Hyper-V (three Critical RCEs + two elevation-of-privilege) and one in the VHD Miniport driver.
Next Issue Preview
- October 19: Proxmox 24/7 enterprise support goes live — we’ll watch the Standard tier’s rollout pace and how the SLA lands in practice;
- KubeVirt v1.10 stable: alpha.0 froze 824 changes; the stable release is expected to follow the Kubernetes 1.37 cadence — we will keep tracking;
- October Patch Tuesday (October 13): will the 974 record be broken? Hyper-V and the VHD components deserve continued attention;
- Once VMware AI Factory’s follow-up technical documentation and MetalSoft integration details are released, we will publish a hands-on analysis.
About this publication: Virtualization Watch (VirtWatch Weekly) is a biweekly virtualization industry publication produced by the ZSvirt community, covering product news, security advisories, and community discussion across VMware/Broadcom, Proxmox, KVM/QEMU, Hyper-V, KubeVirt, Nutanix, and more. It is compiled with AI-cluster assistance; every fact is linked to its source; we aim for balanced viewpoints and welcome corrections. All factual content in this issue was verified against primary sources (official press releases, official blogs, GitHub release pages, original HN posts, etc.), with key source pages captured by the editors. News window: September 1–13, 2026; editorial deadline: September 13, 2026. Visit zsvirt.io for past issues and the video edition.