


Perceptive Security
SOC/SIEM Consultancy

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Published:
29 juli 2026 om 17:31:15
Alert date:
29 juli 2026 om 18:02:53
Source:
thehackernews.com
Cloud & Virtualization, Zero-Day Vulnerabilities, Identity & Access
Broadcom has released security updates addressing multiple critical vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. The most severe is CVE-2026-59309, a CVSS 9.8 authentication bypass in VMware vCenter that allows a malicious actor with network access to bypass authentication. Two additional critical-severity flaws were also patched, enabling remote code execution and virtual machine escape. These vulnerabilities affect widely deployed VMware products used in enterprise environments. The flaws represent significant risk as they can be chained or exploited independently to compromise virtualized infrastructure. Organizations running affected VMware products are urged to apply the security updates immediately.
Technical details
Broadcom disclosed five vulnerabilities across VMware ESX, vCenter, Workstation, and Fusion. Three are critical: (1) CVE-2026-59309 (CVSS 9.8) - Authentication bypass in VMware vCenter allowing unauthenticated remote access via network access. (2) CVE-2026-59310 (CVSS 9.8) - Directory traversal vulnerability in VMware vCenter enabling remote arbitrary code execution by any actor with network access. (3) CVE-2026-47876 (CVSS 9.3) - Out-of-bounds write in the VMXNET3 virtual network adapter of VMware ESX, allowing a local administrative user inside a VM to escape and execute code on the ESX host (VM escape). Two additional flaws: (4) CVE-2026-41703 (CVSS 7.6) - Out-of-bounds read in VMware ESX exploitable by actors with VM deployment privileges, leading to information disclosure or DoS; on Workstation/Fusion limited to information disclosure. (5) CVE-2026-41709 (CVSS 2.7) - Insufficient logging in VMware ESX allowing a malicious administrator to perform operations without audit trails. No in-the-wild exploitation has been observed.
Mitigation steps:
Apply the security updates released by Broadcom immediately for all affected products: upgrade VMware vCenter 8.0 to 8.0 U3k; upgrade VMware Cloud Foundation and vSphere Foundation 9.1.x.x to 9.1.0.0300 and 9.0.x.x to 9.0.2.0100; apply async patch to 8.0 U3k for Cloud Foundation 5.x; update VMware ESX to the respective fixed ESXi builds; update VMware Workstation and Fusion to 26H1; update VMware Cloud Foundation to 5.2.3. Restrict network access to vCenter to trusted networks/hosts. Limit local administrative privileges inside virtual machines, especially those using the VMXNET3 adapter, to reduce VM escape risk. Monitor vCenter authentication logs for unauthorized access attempts. Review audit logs for suspicious activity given the insufficient logging flaw. Consult Broadcom security advisory VMSA-2026-0006 for full remediation guidance.
Affected products:
VMware vCenter 8.0 (fixed in 8.0 U3k)
VMware Cloud Foundation 5.x (Async patch to 8.0 U3k)
VMware Cloud Foundation and VMware vSphere Foundation 9.1.x.x (fixed in 9.1.0.0300)
VMware Cloud Foundation and VMware vSphere Foundation 9.0.x.x (fixed in 9.0.2.0100)
VMware ESX / ESXi (fixed in ESXi-9.1.0.0200-25557999
ESXi-9.0.2.0100-25595025
ESXi80U3k-25595708
ESXi80U3i-25205845
ESXi80U3j-25429389)
VMware Workstation (fixed in 26H1)
VMware Fusion (fixed in 26H1)
VMware Cloud Foundation 5.2.3
Related links:
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2026-0006
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
