Bottom line: Broadcom patches five security vulnerabilities in VMware products, including three critical flaws with auth-bypass and VM-escape potential.
Broadcom has released security updates for VMware vCenter, ESX, Workstation and Fusion to fix five vulnerabilities. Three of them are critical and enable authentication bypass, code execution, and VM-escape to the host level.
Broadcom has released security updates for its VMware portfolio. Affected are vCenter, ESX, Workstation and Fusion. In total, five vulnerabilities are being remediated, three of which are classified as critical.
The critical vulnerabilities allow attackers to bypass authentication mechanisms, execute arbitrary code, or escape from a virtual machine to the host system (VM-escape). Such vulnerabilities pose significant risk to environments with virtualized workloads, particularly when VMs should be tenant-isolated or process sensitive data.
CISOs should prioritize these updates in their patch management processes, as virtualization infrastructure often plays a central role in IT security architecture. Auth-bypass and code execution flaws in such systems can be exploited as a starting point for lateral movement or data access.
Source: www.bleepingcomputer.com · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.