← Back to Feed

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

CVE-2026-59309

July 29, 2026 · The Hacker News · Severity: CRITICAL

Broadcom released security updates for multiple critical VMware vulnerabilities affecting ESX, vCenter, Workstation, and Fusion. Three critical flaws include: CVE-2026-59309 (CVSS 9.8), an authentication bypass in vCenter allowing unauthorized network access; CVE-2026-59310 (CVSS 9.8), a directory-traversal vulnerability in vCenter enabling arbitrary code execution; and CVE-2026-47876 (CVSS 9.3), a use-after-free vulnerability in Workstation and Fusion allowing VM escape. Patched versions include vCenter 8.0 U3k and VMware Cloud Foundation updates.

Key Takeaways

  • Three critical VMware vulnerabilities were disclosed: authentication bypass (CVSS 9.8), directory-traversal RCE (CVSS 9.8) in vCenter, and a VM escape use-after-free (CVSS 9.3) in Workstation/Fusion.
  • The vCenter flaws allow network-based attackers to bypass authentication or execute arbitrary code without credentials, posing severe risk to virtualized infrastructure.
  • Broadcom has released patches for vCenter 8.0 U3k and corresponding Cloud Foundation versions; immediate updating is critical.
☕ Buy a Coffee