Skip to main content
Question

vulnerability mitigation for nutanix-sa-57 security advisory on AOS 7.3

  • October 7, 2026
  • 2 replies
  • 26 views

Please advise on vulnerability mitigation for nutanix-sa-57 security advisory and possible fix release date. We understand that upgrading to AOS 7.6 is the available option at the moment.  The hardware is 3-node Lenovo HX650 V3 cluster.
Please confirm the dark site upgrade sequence with the below bundles is correct, or if it can be done better.


1    LCM Framework Bundle 3.4.0.1
2    NCC LCM Bundle 6.0.0.1
3    Nutanix Compatibility Bundle
4    Prism Central LCM Bundle 7.6
5    Foundation LCM Bundle 5.11
6    AOS LCM Bundle 7.6
7    AHV LCM Bundle 11.3
8    LENOVO Firmware LCM Bundle 3.0
All bundles to be uploaded and run from PE LCM except the "Prism Central Bundle LCM Bundle" from the PC LCM.

2 replies

Forum|alt.badge.img+3
  • Vanguard
  • October 7, 2026

first of all , you have to install the firmware before you upgrade your AHV.
do you have any  feature enabled on your PC?
for AOS 7.6, AHV version is as below, using below link
Nutanix Support & Insights

for dark site, I suggest, create a web site and extract all of what you mentioned in there and let AOS detects them for you.
remember to do an inventory after each component upgrade.

 


LMohammed
Forum|alt.badge.img+2
  • Vanguard
  • October 7, 2026

​@Azam Shariff  Your upgrade order is correct. with a bit of recommendation LCM bundle first, Nutanix compatibility bundle 2nd then NCC and continue 

You can upload directly to your PC and PE just make sure to have enough space to not full the cvm size!
or upload one at a time and then upgarde and delete and move on to the next upgrade.

Prepare your downloads : 

 


this was for one of my previous upgrades.

 



 

LCM Framework Bundle :


Nutanix compatibility bundle :


Then the NCC for both Prism Central and PE.


Continue with upgrading your Prism Central first and once you complete pass to PE.

PE:
- Foundation
- AOS
- AHV

Finally you can upgrade your firmware as well using the ipmi (Direct method/Darksite)