Broadcom has released security updates to address several high-impact vulnerabilities affecting VMware products, including VMware ESX, vCenter Server, Workstation, and Fusion. Among the disclosed issues are three critical vulnerabilities that could allow attackers to bypass authentication, execute arbitrary code, and escape from virtual machines to underlying host systems.
Critical Authentication Bypass in VMware vCenter
The most severe vulnerability, tracked as CVE-2026-59309 with a CVSS score of 9.8, affects VMware vCenter Server and could allow an attacker with network access to bypass authentication mechanisms entirely.
According to Broadcom, a remote attacker could exploit the flaw to gain unauthorized access to vulnerable vCenter environments without valid credentials, potentially compromising the management layer of virtualized infrastructure.
Directory Traversal Flaw Enables Remote Code Execution
Another critical vulnerability, CVE-2026-59310 (CVSS 9.8), is a directory traversal weakness within VMware vCenter. An attacker with network access can leverage the flaw to execute arbitrary code on the target system, creating a pathway for full system compromise.
Both vulnerabilities have been addressed in the following releases:
- VMware Cloud Foundation and VMware vSphere Foundation 9.1.x.x (fixed in 9.1.0.0300)
- VMware Cloud Foundation and VMware vSphere Foundation 9.0.x.x (fixed in 9.0.2.0100)
- VMware vCenter Server 8.0 (fixed in 8.0 U3k)
- VMware Cloud Foundation 5.x (patched via asynchronous update based on vCenter 8.0 U3k)
VM Escape Vulnerability Allows Host-Level Code Execution
Broadcom also patched CVE-2026-47876, a critical out-of-bounds write vulnerability affecting the VMXNET3 virtual network adapter used by VMware ESX environments.
Assigned a CVSS score of 9.3, the flaw allows an attacker with administrative privileges inside a guest virtual machine to break isolation boundaries and execute code directly on the ESX host.
Broadcom categorized the issue as a virtual machine escape vulnerability, one of the most serious classes of virtualization security flaws.
In a successful attack scenario, an adversary who already controls a virtual machine can leverage the vulnerability to compromise the physical host, potentially affecting other virtual machines running on the same infrastructure.
The issue has been resolved in:
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.1.0.0200-25557999
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.0.2.0100-25595025
- VMware ESX ESXi80U3k-25595708
Additional VMware Security Fixes
Broadcom's security release also addresses two other vulnerabilities:
CVE-2026-41703 (CVSS 7.6)
An out-of-bounds read vulnerability affecting VMware ESX that can be triggered by a user with virtual machine deployment privileges.
Potential impacts include:
- Information disclosure
- Denial-of-Service (DoS) conditions
For VMware Workstation and VMware Fusion users, exploitation is limited to information disclosure.
The flaw has been fixed in:
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.1.0.0-25370933
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.0.2.0100-25595025
- VMware ESX ESXi80U3i-25205845
- VMware Workstation 26H1
- VMware Fusion 26H1
- VMware Cloud Foundation 5.2.3
CVE-2026-41709 (CVSS 2.7)
A lower-severity logging flaw affecting VMware ESX that could allow a malicious administrator to perform certain activities without those actions being properly recorded in audit logs.
This issue has been resolved in:
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.1.0.0-25370933
- VMware Cloud Foundation and VMware vSphere Foundation ESXi-9.0.2.0100-25595025
- VMware ESX ESXi80U3j-25429389
No Evidence of Active Exploitation
Broadcom stated that it is currently unaware of any evidence suggesting these vulnerabilities have been exploited in the wild. Nevertheless, given the severity of the flaws, particularly those affecting vCenter and the VMXNET3 adapter, organizations are strongly encouraged to apply the available updates as soon as possible.
Why These Vulnerabilities Matter
VMware infrastructures often host critical business applications, databases, and cloud workloads. Vulnerabilities capable of:
- Bypassing authentication,
- Executing remote code,
- Escaping guest virtual machines, or
- Compromising virtualization hosts
represent significant risks to enterprise environments.
Security teams should prioritize patching affected systems, review access controls around VMware management interfaces, monitor for unusual activity, and validate that all ESX, vCenter, Workstation, and Fusion deployments are running supported and updated versions.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
