Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Memoria por niveles de VMware: NVMe local haciendo de RAM en un servidor ESX
9 min read

NVMe standing in for RAM: memory tiering works if half of yours is idle

VMware refines memory tiering in Cloud Foundation 9.1, available since 9.0: cold pages demoted from DRAM to a local NVMe drive so a host ends up with more memory than you bought. What almost nobody quotes is the recommendation VMware itself published on its blog on 6 August: keep active memory below 50% of physical memory. The requirements, the limits, what is known about the 25% of workloads that does not fit today, and why a memory reservation does not get you out of it.

Chasis de servidor de rack abierto sobre un banco de taller, con la tapa retirada y dos disipadores de procesador a la vista entre los bancos de memoria
8 min read

Azure stops including the VMware licence: the core count nobody does

Two weeks ago we wrote that 31 October 2026 is the end of Azure VMware Solution with the licence included. Microsoft has since published its portable licensing reference, and that is where the counting rules are: how many cores each node type has, why the distributed firewall counts every host in the private cloud even the ones you are not paying for, and which date actually governs your calendar, because it is not the August 2027 one.

Cronómetro deportivo: los cinco días entre el aviso VMSA-2026-0006 y las primeras conexiones de vCenter comprometidos a la infraestructura del atacante
6 min read

The vCenter advisory said there was no known exploitation. It held for five days

Broadcom published VMSA-2026-0006 on 29 July with no information suggesting exploitation, and that is how we quoted it here the next day. On 3 August the first compromised vCenters started connecting to attacker infrastructure, and on 12 August QUIRSO published the count: 361 victim IP addresses across 47 countries. What those numbers mean, what they do not, and the question that decides whether this concerns you: who can open a connection to your vCenter.

El 31 de octubre de 2026 se acaba el modelo de licencia de VMware incluida en los nodos de Azure VMware Solution: a partir del 1 de noviembre hay que aportar una suscripción portable de VMware Cloud Foundation comprada a Broadcom
8 min read

Plan B expires on 31 October: VMware with the licence included is ending in the cloud

On 31 October 2026 the Azure VMware Solution model in which the licence came bundled with the node comes to an end: from 1 November you must bring a VMware Cloud Foundation key bought directly from Broadcom. On Google Cloud VMware Engine it already happened on 1 November 2025. Eighty-nine days to go. For two years, "I will just lift my vSphere into the hyperscaler" has been the favourite plan B for not deciding; it was an extension, and extensions expire. The maths you can finish this week, and when staying put is the right call.

VMSA-2026-0006: dos vulnerabilidades CVSS 9,8 en VMware vCenter y un escape de máquina virtual en ESX
8 min read

VMSA-2026-0006: two 9.8s in vCenter, a VM escape and the flaw nobody will look at

On 29 July 2026 Broadcom published VMSA-2026-0006: five flaws in VMware ESX, vCenter, Workstation and Fusion, two of them CVSS 9.8 in vCenter and one 9.3 that allows escaping from a virtual machine to the host. There are no workarounds. What to patch first according to the advisory itself (the order is no longer the one you knew), why updating vCenter does not stop your workloads, where the patches are if you hold a perpetual licence with no support, and why the lowest-scoring flaw — ESX may not record what an administrator does — is the one that hurts afterwards.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN