Feed›Cloud Security›VMware fixes three critical flaws allowing auth bypass, VM e...
Cloud SecurityBleeping Computer
9.8 — CRITICAL

VMware fixes three critical flaws allowing auth bypass, VM escapes

📅 30 July 2026 at 18:00 UTC📰 Bleeping ComputerView original source ↗
VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

VMware has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

⚙️Technical Details
CVEs
CVE-2026-59309CVE-2026-59310CVE-2026-47876CVE-2026-41703CVE-2026-41709
Affected Systems
VMware vCenterESXWorkstationFusion
Attack Vectors
NETWORKNETWORKLOCAL
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations running versions of VMware vCenter, ESX, Workstation, and Fusion before the fixed versions
🛡️Recommended Actions
1Apply the security updates as soon as possible
2Switch virtual machines away from the VMXNET3 adapter is not advisable due to other virtual network adapters containing security flaws
3Use ESXi Live Patch to reduce disruption during updates
📦Affected Products
VMware vCenterESXWorkstationFusion
🔐NVD Verified DataVERIFIED
CVE-2026-59309 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-303
CVE-2026-59310 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
CVE-2026-47876 ↗CVSS 9.3 — CRITICAL
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-787
CVE-2026-41703 ↗CVSS 7.6 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Weaknesses
CWE-125
CVE-2026-41709 ↗CVSS 2.7 — LOW
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-778

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed