Broadcom has issued security updates for VMware ESX, vCenter, Workstation, and Fusion to fix multiple vulnerabilities, including three critical flaws in vCenter. The issues could allow authentication bypass, arbitrary code execution, VM escape, information disclosure, or insufficient logging, but Broadcom says there is no evidence of in-the-wild exploitation. #CVE-2026-59309 #CVE-2026-59310 #CVE-2026-47876 #VMwarevCenter #VMwareESX #VMXNET3
Keypoints
- Broadcom patched multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion.
- CVE-2026-59309 is a critical authentication bypass in VMware vCenter.
- CVE-2026-59310 is a critical directory-traversal flaw that can lead to arbitrary code execution.
- CVE-2026-47876 is an out-of-bounds write in VMXNET3 that may allow code execution on the ESX host.
- Broadcom said none of the flaws appear to have been exploited in the wild.
Read More: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html