← Back to Feed

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

CVE-2026-59309

July 29, 2026 · The Hacker News · Severity: CRITICAL

Broadcom has issued urgent security updates to address multiple critical vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Three of these flaws are rated critical, with CVSS scores ranging from 9.8 to 9.3. The first, CVE-2026-59309, allows an attacker with network access to bypass authentication on VMware vCenter, granting unauthorized system access. The second, CVE-2026-59310, is a directory-traversal vulnerability in vCenter that enables arbitrary code execution. The third, CVE-2026-47876, is a virtual machine escape flaw in the VMXNET3 virtual network adapter of VMware ESX, allowing a malicious actor with local administrative privileges on a virtual machine to execute code on the host. Additional vulnerabilities, including CVE-2026-41703 and CVE-2026-41709, pose risks of information disclosure, denial-of-service, and insufficient logging. These vulnerabilities impact VMware Cloud Foundation, VMware vSphere Foundation, VMware vCenter, VMware Workstation, and VMware Fusion users. Broadcom has released patches for affected versions, including VMware Cloud Foundation 9.1.x.x, VMware vSphere Foundation 9.0.x.x, VMware vCenter 8.0, and VMware ESX ESXi80U3k. While there is no evidence of exploitation in the wild, the company has categorized these updates as emergency changes requiring immediate action. The severity of these flaws underscores the importance of prompt patching to prevent potential unauthorized access, code execution, and virtual machine escape attacks.

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said. The second critical flaw is a directory-traversal vulnerability in vCenter ( CVE-2026-59310 , CVSS score: 9.8) that a malicious actor with network access can exploit to execute arbitrary code. Both vulnerabilities have been addressed in the versions below - VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300) VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100) VMware vCenter version 8.0 (Fixed in 8.0 U3k) VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k) Also patched by Broadcom are three other flaws - CVE-2026-47876 (CVSS score: 9.3) - An out-of-bounds write vulnerability in the VMXNET3 virtual network adapter of VMware ESX that a malicious actor with local administrative privileges on a virtual machine can exploit to execute code on the host. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708) CVE-2026-41703 (CVSS score: 7.6) - An out-of-bounds read vulnerability in VMware ESX that a malicious actor with VM deployment privileges could trigger, potentially leading to information disclosure or a denial-of-service (DoS) condition. On VMware Workstation and Fusion, the impact is limited to information disclosure. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3) CVE-2026-41709 (CVSS score: 2.7) - An insufficient logging vulnerability in VMware ESX that a malicious administrator can exploit to perform certain operations without them being logged. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389) Broadcom noted that it has found no evidence to suggest any of these issues have been exploited in the wild. However, there are no available workarounds, and the company has categorized the updates as an emergency change requiring immediate action. The technology giant also characterized CVE-2026-47876 as a virtual machine escape. "An attacker who already holds local administrative privileges inside a virtual machine that uses the VMXNET3 virtual network adapter may execute code on the ESX host," it said . Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter.
☕ Buy a Coffee