DEV Community

ZSvirt
ZSvirt

Posted on

VirtWatch Weekly 001: ZSvirt Core IaaS Engine Goes Open Source, VMware Explore 2026 Kicks Off, Proxmox VE 8 Reaches EOL

Virtualization Watch — Issue 001

August 31, 2026 · Weekly · Coverage window: 8/26–8/31 (with August backfill)

From the Editor

Issue 001 goes to print at the confluence of several timelines: two weeks ago (August 14), this publication's producer ZSvirt fully open-sourced its core IaaS engine, and this week it launched the Storytellers program aimed at creators — a "house matter" we'd like to explain to readers first; today (August 31), VMware Explore 2026 opens in Las Vegas, where Broadcom-era VMware will tell the "private AI cloud" story for another year; on the same day, Proxmox VE 8 officially reaches end of life, closing the book on one of the most widely deployed generations in the open-source camp. The enterprise giant's annual show and the community distribution's version transition each turn a new page on the same Monday.

Over the past two weeks, vCenter's CVE-2026-59310 escalated from a "just-patched" advisory into an in-the-wild attack campaign spanning 47 countries — a reminder that security debt on the management plane always gets called in at the least convenient moment. Meanwhile in the community, vphone-cli — a tool that boots a virtual iPhone with a single command — hit the Hacker News front page, as virtualization keeps breaking out in small, elegant ways.

This week we chase no hype, only verified facts and sources. On to the stories.

In This Issue

ZSvirt's Core IaaS Engine Goes Open Source (GPL-3.0)

On August 14, ZSvirt imported the full source code of its main repository to GitHub (ZSvirt/zsvirt) and open-sourced it under the GPL-3.0 license. It's a "core IaaS engine and cloud infrastructure foundation": the repo includes complete modules for compute, storage, network, identity, image, console, and portal; the primary languages are Java (78.2%) and Groovy (19.4%); and the repository topic tags span KVM, Proxmox, VMware/vSphere and more — positioning it directly against mainstream virtualization management stacks.

A little over two weeks after open-sourcing, the repository has gained 1.5k Stars, 290 Forks, and 103 Watches. There is no formal Release yet — it's in the "full code public, release cadence yet to start" phase, suitable for readers who want to follow the architecture and source code early by watching the repository.

ZSvirt Repo

Alongside the open-source release, the community operations side has kicked off the "ZSvirt Storytellers — Phase 1: YouTube Challenge" (published August 28 in GitHub Discussion #8): record one ZSvirt-themed YouTube video and earn rewards tiered by views — $100 for ≥500 views, $150 for ≥1,000 views, $200 for ≥2,000 views, plus a +$20 bonus for the first creator from each region; limited to 20 participants, with submissions due September 28 and settlement on September 30. The baseline requirement is to fully demonstrate "from ISO install to dashboard up and running"; there are three optional advanced directions: comparison with Proxmox/VMware, migrating existing VMs from VMware/Proxmox, and a snapshot create-break-restore drill. One video per person; view inflation disqualifies entries. Interested readers can sign up directly at Discussion #8.

ZSvirt Storytellers YouTube Challenge details

Sources: GitHub: ZSvirt/zsvirt · Discussion #8: ZSvirt Storytellers — Phase 1: YouTube Challenge

VMware Explore 2026 Opens Today in Las Vegas (8/31–9/3)

VMware's annual conference, Explore 2026, opens today at the Venetian in Las Vegas for a four-day run. Based on Broadcom's official disclosure and VMware's pre-show blog posts:

  • Scale: more than 400 breakout sessions, plus Hands-on Labs and certification courses;
  • Keynote: the opening keynote is "Shaping the Future of Private AI Cloud and Agentic Innovation" (session PLE1837LV, 4:00 PM Pacific on 8/31), led by Ram Velaga, president of Broadcom's Infrastructure Software Group, joined by Paul Turner, VP of Products for the VCF division, and Purnima Padmanabhan, GM of the Tanzu division — private AI cloud and agentic applications are the definitive through-line of this show. The general session is open only to Full Event Pass holders on a first-come, first-served basis, with overflow simulcasts at The Hub and Bellini 2103;
  • Certification incentive: the Full Event Pass includes a VCAP exam voucher — a real subsidy for anyone pursuing certifications;
  • Global tour: after Las Vegas, Explore on Tour heads to Mumbai (9/29–30), Singapore (10/1–2), Frankfurt (10/13–14), Tokyo (10/20–21), London (11/18–19), and Washington (12/8), wrapping up in Sydney on March 3–4, 2027.

We will keep tracking VCF (VMware Cloud Foundation) releases and product announcements during the show and consolidate them in the next issue.

Broadcom's official press release: VMware Explore 2026

Sources: Broadcom IR: VMware Explore 2026 press release · VMware Explore 2026 official site

Proxmox VE 8 Reaches End of Life Today

Also on August 31, Proxmox VE 8 reaches the end of its official lifecycle. This generation, based on Debian 12 (Bookworm), was released in June 2023 and has been the workhorse platform for countless home labs and SMBs. Per Proxmox's official support matrix, VE 8 support ends in August 2026 — today. Nodes still running 8.x should already be seeing the EOL banner in their web management UI.

The upgrade path isn't complicated, but both official and community guidance stress "check first, then act":

  1. Confirm backups are in place (PBS or offline copies);
  2. Run the pve8to9 checker on every 8.x node, clearing blocking items one by one;
  3. Follow the official upgrade documentation to roll each node up to VE 9 (based on Debian 13) — for clusters, upgrade standby nodes first, migrate workloads, then upgrade primary nodes.

Virtualization Howto's Brandon Lee reminded readers in his August 19 guide: don't treat EOL as a countdown to immediate downtime, but don't keep putting it off either — after EOL there are no more security updates, and the exposure surface only grows over time.

Virtualization Howto: What to do before PVE 8 EOL

Sources: Virtualization Howto upgrade guide · Proxmox VE lifecycle

Product & Version News

QEMU 11.1.1 / 11.0.4 / 10.0.13 Released on Three Lines in Sync (8/26)

On August 26, QEMU shipped maintenance releases for three stable branches in sync: 11.1.1, 11.0.4, and 10.0.13 — all fix-oriented point releases, with source packages up on qemu.org signed with GPG. Shipping three lines on the same day is uncommon in QEMU's release history; distributions and cloud platforms running multiple concurrent versions should check their changelogs and assess whether to adopt them.

QEMU official download page

Source: QEMU official download page

Nutanix FY2026 Q4 Earnings: ARR $2.55B, Up 16% YoY (8/26)

Nutanix reported its fiscal Q4 (quarter ended July 31) and full-year FY2026 results: Q4 ARR of $2.55 billion (+16% YoY), quarterly revenue of $757.1 million (+16%), non-GAAP operating margin of 26.2% (up 790 basis points YoY), and free cash flow of $277.6 million; more than 3,000 net-new customers added during the year. CEO Rajiv Ramaswami called out new or deepened partnerships with AMD, Lenovo, NetApp, and NVIDIA, with AI and external storage support as key platform investment areas. With Broadcom's channel policy tightening, Nutanix's report is one of the most direct footnotes to the "VMware replacement" narrative.

Nutanix FY26 Q4 earnings press release

Source: Nutanix IR press release

Backfill

  • Proxmox VE 9.2 debuts official Arm64 support (8/5): in early August, Proxmox announced PVE officially landing on 64-bit ARM, delivered on VE 9.2, bringing ARM servers and edge devices into the official support matrix. The announcement was still pinned on r/Proxmox this week.
  • VirtualBox 7.2.16 (mid-August): Oracle shipped a 7.2-series maintenance update fixing multiple guest and network-stack issues.
  • VMware Workstation 26H1 / Fusion 26H1 GA: r/vmware's pinned announcement this week shows both desktop virtualization products reached GA with the 26H1 releases.

Sources: Proxmox press release list · r/vmware pinned announcement

Community Buzz

HN Front Page: Boot a Virtual iPhone with One Command (vphone-cli, 406 points / 111 comments)

This week's hottest virtualization-related post on Hacker News is "Boot a Virtual iPhone via Apple's Virtualization.framework": the open-source project vphone-cli uses the iOS kernel Apple ships in PCC (Private Cloud Compute)/cloudOS images, combined with the iOS userland and patches, to boot a "virtual iPhone" on Apple Silicon Macs via direct virtualization. The technical consensus in the HN thread: this isn't a Corellium-style emulator — it's real virtualization, and apps can easily tell it apart from a real device. Commenters also remind: don't pick Japan or the EU region during setup (the VM can't pass third-party app-store compliance checks). The repo has reached 9.7k Stars and 1.3k Forks, primarily in Swift.

HN discussion page

Sources: Hacker News discussion · GitHub: Lakr233/vphone-cli

Reddit This Week

  • r/Proxmox: the pinned post is indeed "Proxmox VE now available for 64-bit ARM (arm64)!" (551 votes / 119 comments) — community enthusiasm for ARM support exceeded expectations, with discussion focused on ARM server form factors beyond the Raspberry Pi and how to obtain images;
  • r/vmware: the VMSA-2026-0006 patch discussion thread (88 votes / 148 comments) has effectively become the "patch exchange center," with upgrade ordering and VCF-environment considerations as the main topics; two hands-on threads also ranked high — 100 GbE NIC tuning (a ConnectX-6 Dx only reaching 43 Gbit/s) and vCPU:pCPU oversubscription ratios.

r/Proxmox weekly hot posts

Sources: r/Proxmox weekly top · r/vmware weekly top

Security Advisories

Tracking VMSA-2026-0006: Timeline of CVE-2026-59310 Exploitation

On July 29, Broadcom published VMSA-2026-0006 (updated to .2 on August 19), fixing five vulnerabilities across ESX / vCenter / Workstation / Fusion. Two of the vCenter flaws are both CVSS 9.8:

  • CVE-2026-59310: a directory-traversal vulnerability in the vCenter Syslog service that can be used for unauthenticated remote code execution;
  • CVE-2026-59309: an authentication-bypass vulnerability in VMware Directory Service.

In-the-wild exploitation: German incident-response firm QUIRSO confirmed the attacks began on August 3 — just five days after disclosure. As of its August 10 report, 361 distinct victim IPs had been recorded across 47 countries, with Germany (55), the United States (41), Turkey (38), Iran (26), and France (25) accounting for about half. The attack chain: directory traversal to write and execute arbitrary code → plant cron jobs → launch the open-source reverse-shell framework reverse_ssh to establish outbound C2, bypassing defenses focused on inbound detection. The Cloud Security Alliance's analysis note points out that because vCenter is the control plane of the entire virtualization environment, compromise means control over all managed hosts, VMs, and snapshots.

Ransomware follow-up: The Hacker News reports that some attackers deployed Babuk-derived ransomware (.babyk) on compromised vCenters. QUIRSO attributes the campaign to Chinese-language-context attackers with "medium confidence" (based on Chinese traces in scripts, tool reuse, and UTC+8 operating rhythms). We'd note: attribution carries uncertainty, and 361 victim IPs do not equal 361 organizations.

Remediation advice: the CVE has been added to CISA's KEV catalog. Broadcom confirms there is no workaround — the only effective option is to upgrade to fixed versions: vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f. Security teams can prioritize hunting for: anomalous cron jobs, outbound reverse_ssh connections, and abnormal Syslog-service writes.

Broadcom VMSA-2026-0006 advisory

The Hacker News report

Sources: Broadcom VMSA-2026-0006 · The Hacker News · CSA research note

Tools & Good Reads

  • vphone-cli: boot iOS on Apple Silicon via virtualization with one command — this week's most talked-about open-source project (see Community Buzz);
  • ixui: a pre-alpha Incus web UI — "Proxmox's skin, ESXi's bones," with hand-written React components, a cluster-aware instance tree, and a working SPICE console; fine for tinkering, not for production;
  • Virtualization Howto's PVE 8 EOL guide: the pre-EOL checklist and pve8to9 usage essentials;
  • LWN: multikernel patch series: a proposal to run multiple Linux kernels simultaneously on one bare-metal machine hit the HN hot list, adding a new variable to the old "kernel-level isolation vs. virtualization" debate.

Sources: GitHub: vphone-cli · GitHub: ixui · Virtualization Howto

Number of the Week

47 — the number of countries hit by the in-the-wild exploitation of CVE-2026-59310 (per QUIRSO's August 10 report, 361 victim IPs). Only five days separated patch release from weaponization: the management-plane patch window is narrowing to days.

Next Issue Preview

A recap of announcements from VMware Explore 2026 (VCF version developments, private-AI-cloud products), feedback on Proxmox VE 9 upgrades, and more voices from the community frontline. See you next issue.


About this publication: Virtualization Watch (VirtWatch Weekly) is a virtualization industry weekly produced by the ZSvirt community, published every Sunday, covering product news, security advisories, and community discussion across global virtualization and cloud infrastructure. It is compiled with AI-cluster assistance; every fact is linked to its source; we aim for balanced viewpoints and welcome corrections. Visit zsvirt.io for past issues and the video edition.

Top comments (0)