Broadcom has released emergency security updates for five VMware vulnerabilities, including three critical flaws that could allow authentication bypass, remote code execution and virtual machine escapes.

The VMware critical vulnerabilities affect vCenter, ESX, Workstation and Fusion. They also affect products that include vCenter or ESX, such as VMware Cloud Foundation, VMware vSphere Foundation and VMware’s telco platforms.

Broadcom urged organisations running affected versions to patch immediately.

Three critical VMware flaws need urgent patching

Two critical flaws affect VMware vCenter and both carry CVSS scores of 9.8.

CVE-2026-59309 is an authentication bypass in the VMware Directory Service. An unauthenticated attacker with network access to vCenter could exploit it to gain unauthorised access.

CVE-2026-59310 is a directory traversal flaw in the vCenter Syslog server. It could allow an unauthenticated network attacker to execute arbitrary code.

The third critical issue, CVE-2026-47876, affects the VMXNET3 virtual network adapter. It has a CVSS score of 9.3.

An attacker with local administrator privileges inside an affected virtual machine could exploit the flaw to execute code on the ESX host. This would allow the attacker to escape the virtual machine environment.

Only virtual machines using VMXNET3 are affected by this issue.

Two further flaws affect ESX, Workstation and Fusion

Broadcom also fixed CVE-2026-41703, an out-of-bounds read vulnerability in ESX, Workstation and Fusion.

On ESX, an attacker with virtual machine deployment privileges could disclose information or cause a denial-of-service condition in the host process. It has a CVSS score of 7.6.

The impact is lower on Workstation and Fusion, where the flaw is limited to information disclosure. It is rated Low with a CVSS score of 2.7.

The fifth issue, CVE-2026-41709, is an insufficient logging vulnerability in ESX. A malicious ESX administrator could use it to carry out certain actions without those actions being logged. Broadcom rated it Low, with a CVSS score of 2.7.

Updated versions are now available

The vCenter flaws are fixed in vCenter versions 9.1.0.0300, 9.0.2.0100 and 8.0 Update 3k.

The ESX vulnerabilities are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100 and ESXi 8.0 Update 3k.

Workstation and Fusion users running version 25H2 must upgrade to version 26H1 to fix CVE-2026-41703.

VMware Cloud Foundation 5.x and affected telco products have separate patching instructions.

There are no workarounds. Broadcom also advised against switching virtual machines away from VMXNET3, noting that other adapters have also contained security flaws and may reduce performance.

Patching may disrupt management access

Broadcom classed the updates as an emergency change under ITIL methodology.

Patching vCenter will temporarily interrupt access to the vSphere Client and other management interfaces. However, running virtual machines and containers will continue operating.

ESX updates require hosts to restart. Administrators should use vMotion to move virtual machines to other hosts during rolling cluster reboots. Virtual machines that cannot be moved must be powered down during the restart.

Supported environments can use ESX Live Patch to reduce disruption. The vCenter updates are not eligible for Quick Patch.

Broadcom also warned that installing some of the vSphere 8.0 and 9.0 updates may temporarily block planned upgrades to VMware Cloud Foundation 9.x. This happens because of a “back in time” build compatibility restriction. The company said later releases will restore upgrade compatibility.

No active exploitation reported

Broadcom said it has not seen evidence that attackers are exploiting these vulnerabilities in the wild.

However, VMware infrastructure remains a high-value target. A compromise of vCenter or ESXi can expose large numbers of servers and the data stored on them.

Ransomware groups have long used dedicated encryptors against VMware virtual machines. In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to deploy BrickStorm malware, create hidden rogue virtual machines and steal cloned VM snapshots.

CrowdStrike has separately observed attackers creating unregistered “ghost” virtual machines through the ESXi shell. The technique, called VirtualGHOST, can provide persistence while avoiding visibility in ESXi and vCenter consoles.

Administrators should apply Broadcom’s emergency updates as soon as possible.


0 responses to “VMware Fixes Three Critical Flaws That Allow Auth Bypass and VM Escapes”