To the point: Three critical VMware vulnerabilities (CVSS 9.3–9.8) enable authentication bypass, remote code execution, and VM escape; Broadcom recommends immediate patching as no workarounds are available.
Broadcom has released security updates for VMware ESX, vCenter, Workstation, and Fusion, closing three critical vulnerabilities that allow attackers to take over vCenter or break out of virtual machines.
Broadcom has patched five vulnerabilities in its virtualization software, including three rated as critical. The most severe, CVE-2026-59309 (CVSS 9.8), is an authentication bypass in VMware Directory Service within vCenter. An attacker with network access can bypass authentication and gain unauthorized access to the system. The second critical vulnerability, CVE-2026-59310 (CVSS 9.8), is a directory traversal weakness in vCenter that allows an attacker with network access to execute arbitrary code. Both vulnerabilities are patched in vCenter Server 8.0 U3k as well as in VMware Cloud Foundation and vSphere Foundation from version 9.1.0.0300 and 9.0.2.0100 respectively.
The third critical vulnerability, CVE-2026-47876 (CVSS 9.3), is an out-of-bounds write flaw in VMware ESX’s virtual network adapter VMXNET3. An attacker with local administrator privileges within a virtual machine can exploit this vulnerability to execute code on the underlying ESX host – Broadcom describes this as a virtual machine escape. Virtual machines using other network adapters are not affected.
Additionally, Broadcom has patched two further vulnerabilities: CVE-2026-41703 (CVSS 7.6) is an out-of-bounds read flaw in ESX, Workstation, and Fusion that can lead to information disclosure or denial of service. CVE-2026-41709 (CVSS 2.7) is insufficient logging in ESX that allows a malicious administrator to perform certain actions without leaving a log entry.
According to Broadcom, there is no evidence that these vulnerabilities have already been exploited. However, as no workarounds are available, the company classifies the released updates as an urgent security advisory requiring immediate action. CISOs should begin rolling out patches without delay, particularly for vCenter instances and ESX hosts with VMXNET3 adapters.
Source: www.it-daily.net · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification through Lumi News Pipeline v1.7.3.