Skip to content
Tech News
← Back to articles

VMware fixes three critical flaws allowing auth bypass, VM escapes

read original more articles
Why This Matters

The recent security updates from Broadcom address three critical vulnerabilities in VMware products that could allow attackers to bypass authentication, execute arbitrary code, or escape from virtual machines to the host system. These flaws pose significant risks to organizations relying on VMware infrastructure, emphasizing the urgent need for prompt patching to safeguard sensitive data and maintain system integrity.

Key Takeaways

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.

The five vulnerabilities are summarized below:

CVE-2026-59309: A critical authentication bypass vulnerability in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system.

A critical authentication bypass vulnerability in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system. CVE-2026-59310: A critical directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker with network access to execute arbitrary code.

A critical directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker with network access to execute arbitrary code. CVE-2026-47876: A critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape. Virtual machines using other virtual network adapters are not affected.

A critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape. Virtual machines using other virtual network adapters are not affected. CVE-2026-41703: An out-of-bounds read vulnerability in ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges could exploit it to disclose information or cause a denial-of-service condition in the host process. On Workstation and Fusion, the impact is limited to information disclosure.

An out-of-bounds read vulnerability in ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges could exploit it to disclose information or cause a denial-of-service condition in the host process. On Workstation and Fusion, the impact is limited to information disclosure. CVE-2026-41709: An insufficient logging vulnerability that allows a malicious ESX administrator to perform certain operations without them being logged.

The three critical vulnerabilities are the two vCenter flaws, CVE-2026-59309 and CVE-2026-59310, which have CVSS scores of 9.8, and the VMXNET3 escape flaw, CVE-2026-47876, which is rated 9.3.

... continue reading