Broadcom has released security updates addressing multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion, including three critical-severity flaws. The most severe is CVE-2026-59309 (CVSS 9.8), an authentication bypass in VMware vCenter that allows network-based attackers to gain unauthorized access. Another critical flaw, CVE-2026-59310 (CVSS 9.8), is a directory-traversal vulnerability in vCenter enabling arbitrary code execution. Both are fixed in VMware Cloud Foundation, vSphere Foundation, and vCenter versions listed by Broadcom.
A third critical issue, CVE-2026-47876 (CVSS 9.3), is an out-of-bounds write in the VMXNET3 virtual network adapter of VMware ESX, which can be exploited by an attacker with local admin privileges on a VM to execute code on the host—effectively a VM escape. Additional flaws include CVE-2026-41703 (CVSS 7.6), an out-of-bounds read in ESX leading to information disclosure or denial-of-service, and CVE-2026-41709 (CVSS 2.7), an insufficient logging vulnerability in ESX. Broadcom has not observed any of these issues being exploited in the wild.
Organizations using affected VMware products are urged to apply the patches immediately to mitigate risks of authentication bypass, remote code execution, and virtual machine escape.
CVEs: CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709, CVE-2026-50522
Products: VMware vCenter, VMware ESX, VMware Cloud Foundation, VMware vSphere Foundation, VMware Workstation, VMware Fusion, VMXNET3
Original source: thehackernews.com