VMware fixes three critical flaws allowing auth bypass, VM escapes

VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has issued emergency patches for five VMware vulnerabilities affecting vCenter, ESX, Workstation, and Fusion, including three critical flaws that could let attackers bypass authentication, execute code, or escape a virtual machine to the host. Administrators of VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud products should update immediately, as Broadcom says there are no workarounds and no evidence of active exploitation yet. #Broadcom #VMware #vCenter #ESX #VMXNET3 #VMwareCloudFoundation #VMwarevSphereFoundation #VMwareTelcoCloudPlatform #VMwareTelcoCloudInfrastructure

Keypoints

  • Broadcom fixed five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion.
  • CVE-2026-59309 enables authentication bypass in VMware Directory Service.
  • CVE-2026-59310 allows arbitrary code execution through the vCenter Syslog server.
  • CVE-2026-47876 can let an attacker escape from a VM to the ESX host via VMXNET3.
  • Admins should apply the emergency updates immediately, as there are no workarounds.

Read More: https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/