Cloud SecurityBleeping Computer
9.8 — CRITICAL
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
VMware has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
⚙️Technical Details
CVEs
CVE-2026-59309CVE-2026-59310CVE-2026-47876CVE-2026-41703CVE-2026-41709
Affected Systems
VMware vCenterESXWorkstationFusion
Attack Vectors
NETWORKNETWORKLOCAL
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Organizations running versions of VMware vCenter, ESX, Workstation, and Fusion before the fixed versions
🛡️Recommended Actions
1Apply the security updates as soon as possible
2Switch virtual machines away from the VMXNET3 adapter is not advisable due to other virtual network adapters containing security flaws
3Use ESXi Live Patch to reduce disruption during updates
📦Affected Products
VMware vCenterESXWorkstationFusion
🔐NVD Verified DataVERIFIED
CVE-2026-59309 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-303
CVE-2026-59310 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-22
CVE-2026-47876 ↗CVSS 9.3 — CRITICAL
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-787
CVE-2026-41703 ↗CVSS 7.6 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LWeaknesses
CWE-125
CVE-2026-41709 ↗CVSS 2.7 — LOW
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NWeaknesses
CWE-778
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
