VMware Security Patch Download Issues – Solutions
VMware Perpetual License Holders Face Patch Delays Amid Broadcom Transition
Table of Contents
VMware’s recent shift to subscription-based licensing under Broadcom has left some perpetual license holders in a precarious position, as they are currently unable to access critical security patches for their virtualization environments. This situation raises meaningful concerns about the security posture of organizations that have not transitioned to Broadcom’s new subscription model.
Security Patch Access Blocked for Legacy Users
Reports indicate that a segment of VMware’s perpetual license holders are experiencing difficulties downloading essential security patches.The Register first highlighted the issue, noting that VMware has stated these users will receive the patches “at a later date,” leaving them uncertain about the duration of their exposure to potential vulnerabilities.
The challenges stem from Broadcom’s decision to discontinue perpetual license sales following its acquisition of VMware. This move pushed many organizations towards bundled subscription-based SKUs. However, some customers have opted to continue using their existing VMware products without a new support contract. While these users where expected to retain access to critical security patches, the current portal limitations are preventing downloads.
VMware customer service has reportedly informed some affected customers that they might have to wait up to 90 days for patch access, according to The Register. This delay is particularly concerning given VMware’s recent disclosure of three critical flaws in eight of its offerings on July 15th, including those addressed in VMware Security Advisory 2025-0013.
Broadcom’s Stance on Patch Availability
A Broadcom spokesperson addressed the situation, stating, “Nothing has changed in Broadcom’s commitment regarding critical VMware security patches.” The company asserts that users of legacy VMware products without active maintenance and support entitlements will continue to receive free access to critical security patches for the supported lifespan of those products.
Though, the spokesperson clarified that the current support portal requires validation of customer entitlements for software patches, which is why only entitled customers have access at this time. Affected customers have been informed that they will receive the patches “at a later date” through a “separate patch delivery cycle,” though no specific timeline has been provided. Broadcom has declined to disclose the number of users impacted by this delay.
Broader Implications of the Broadcom Acquisition
The delay in security patch delivery for perpetual license holders is occurring amidst ongoing scrutiny of Broadcom’s acquisition of VMware. The Cloud Infrastructure Services Providers in Europe (CISPE) trade association has filed an appeal with the European General Court, challenging the European Commission’s approval of the deal. CISPE is seeking the annulment of the Commission’s approval, citing concerns about the acquisition’s impact on the market.
Broadcom’s approach to perpetual license holders has also included sending audit letters, further pressuring these organizations to transition to the new subscription model. This combination of restricted patch access and increased audit activity suggests a strategic effort by Broadcom to encourage a complete migration to its subscription services, potentially leaving a segment of its customer base vulnerable in the interim.
The uncertainty surrounding patch availability for critical vulnerabilities highlights the risks associated with the ongoing transition and underscores the importance of clear communication and timely support for all VMware customers, regardless of their licensing model.
