Skip to content

VMware ESXi, vCenter Server, Workstation, and Fusion: Multiple Vulnerabilities Enable DoS and Code Execution

Bottom line: Multiple vulnerabilities in central VMware products allow attackers to conduct DoS attacks, execute code, and bypass security measures.

Several vulnerabilities have been identified in VMware ESXi, vCenter Server, Workstation, and Fusion that attackers can exploit for denial-of-service attacks, information disclosure, security bypass, and remote code execution.

According to CERT-Bund, multiple vulnerabilities in VMware products ESXi, vCenter Server, Workstation, and Fusion have been disclosed. The vulnerabilities enable attackers to create denial-of-service conditions, disclose sensitive information, bypass existing security measures, and execute arbitrary code.

The affected products span both the infrastructure layer (ESXi, vCenter Server) and client virtualization (Workstation, Fusion). This means for CISOs a potential exposure surface across multiple layers of a typical organization’s virtualization landscape.

It is recommended to conduct a detailed analysis of the affected versions and promptly evaluate patches or workarounds. The CERT-Bund advisory under WID-SEC-2026-2569 contains further technical details and information on available fixes.


Source: wid.cert-bund.de · Published 29 July 2026
Lumi AI News — AI-assisted curation according to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: