Broadcom has released security updates to address multiple critical vulnerabilities affecting VMware products, including vCenter Server, ESX, Workstation, Fusion, Cloud Foundation, and Telco Cloud platforms. Researchers said the vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, escape virtual machines, disclose sensitive information, and reduce audit visibility.
The most critical vulnerability, CVE-2026-59309 (CVSS 9.8), is an authentication bypass flaw in the VMware Directory Service. An attacker with network access to a vulnerable vCenter Server can gain unauthorized access to the management plane without valid credentials, potentially taking full control of the virtual infrastructure and hosted workloads.
Another critical vulnerability, CVE-2026-59310 (CVSS 9.8), affects the vCenter Syslog service and allows directory traversal that can lead to remote code execution. Successful exploitation could enable attackers to establish a foothold within the environment and conduct further lateral movement.
VMware ESX is also impacted by CVE-2026-47876 (CVSS 9.3), an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A local administrator inside a guest virtual machine could exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape and host compromise. Additional vulnerabilities may expose sensitive information, cause denial-of-service conditions, or allow administrative actions to occur without sufficient audit logging.
Organizations using affected VMware products should immediately apply the latest security updates, particularly for internet- or network-accessible vCenter servers and ESX hosts, to reduce the risk of infrastructure compromise.
Severity:
High
Attack Surface:
Infrastructure, System Management Service, Workspace
Tactics:
Initial Access, Privilege Escalation, Execution, Defense Evasion, Lateral Movement, Impact
Techniques:
T1078 – Valid Accounts
T1190 – Exploit Public-Facing Application
T1211 – Exploitation for Defense Evasion
T1068 – Exploitation for Privilege Escalation
T1059 – Command and Scripting Interpreter
T1611 – Escape to Host
T1006 – Direct Volume Access
References:
SuperPRO’s Threat Countermeasures Procedures:
1. Upgrade VMware Cloud Foundation and vSphere Foundation 9.1.x.x to version 9.1.0.0300 to address CVE-2026-59309 and CVE-2026-59310 authentication bypass and code execution flaws
2. Upgrade VMware Cloud Foundation and vSphere Foundation 9.0.x.x to version 9.0.2.0100 to patch critical vCenter vulnerabilities
3. Update VMware vCenter 8.0 installations to version 8.0 U3k and apply async patches for VMware Cloud Foundation 5.x environments
4. Deploy ESX patches ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025 to remediate CVE-2026-47876 VMXNET3 VM escape vulnerability
5. Update VMware ESX 8.0 hosts to build ESXi80U3k-25595708 to address out-of-bounds write in virtual network adapter
6. Upgrade VMware Workstation and Fusion to version 26H1 to fix CVE-2026-41703 out-of-bounds read information disclosure flaw
7. Restrict network access to vCenter servers using firewall rules and network segmentation until patches are applied to mitigate remote exploitation risk
Contributed by: Fatini