VxRail: How to manually update ESXi nodes

Summary: This article outlines the procedure for managing customer Service Requests (SR) to address security vulnerabilities (VMSA) in VxRail or VCF On VxRail environments through manual updating. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

VMware by Broadcom periodically issues advisories to address security vulnerabilities. The following steps detail the manual update options to mitigate security risks in VMware infrastructure. This is in case there is a delay in VxRail/VCF upgrade releases, or the customer is unable to perform a full upgrade due to any circumstances. 

Cause

This is in case there is a delay in the VxRail/VCF upgrade release, or the customer is unable to perform a full upgrade due to any circumstances. 

Resolution

Dell VXRAIL HIGHLY RECOMMNEDS THAT CUSTOMERS WAIT FOR THE VXRAIL OR VCF-ON-VxRail VERSIONS THAT INCLUDE THE FIXES

Procedures to upgrade ESXi on hosts outside of a VxRail, or VCF-on-VxRail upgrade.

It is advised to update one host at a time due to vSAN FTT=1 limitation.

Manual updating may trigger VxRail Manager noncompliance alarms in vCenter. The ESXi version does not match the version aligned with the VxRail build which triggers the alarm. This may impact on future upgrades which require support interaction to remediate.
 

  1. Upload the ESXi patch to the service datastore on each host. 
  2. Place the node into Maintenance Mode with the Ensure Accessibility option.

    Screenshot showing the maintenance mode selections 
     
  3. Run the following commands:

    The version below is used for reference in the Knowledge Base (KB). The original fixed version may differ from the version used in the command example. 

     
    # esxcli software sources profile list --depot='/<patch_location>/VMware-ESXi-7.0U3s-24585291-depot.zip'
    # esxcli software profile update -p ESXi-7.0U3s-24585291-standard --depot='/<patch_location>/VMware-ESXi-7.0U3s-24585291-depot.zip' 

     
    Screenshot showing the command output   Screenshot of the update execution from command line 

    Use --no-hardware-warning argument in the command, to bypass the hardware check, if needed.

    esxcli software profile update -d /vmfs/volumes/*-datastore-name*/VMware-ESXi-8.0U2d-24585300-depot.zip -p ESXi-8.0U2d-24585300-standard --no-hardware-warning
     
  4. Reboot the node and take it out from the Maintenance-mode.
  5. Repeat the steps on the remaining nodes, one at a time.

Affected Products

VxRail, VxRail 460 and 470 Nodes, VxRail Appliance Series, VxRail G Series Nodes, VxRail D Series Nodes, VxRail E Series Nodes, VxRail P Series Nodes, VxRail S Series Nodes, VxRail Software, VxRail V Series Nodes

Products

VxRail VD Series Nodes
Article Properties
Article Number: 000345284
Article Type: Solution
Last Modified: 12 Mar 2026
Version:  5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.