Posted in

Broadcom Patches Critical VMware Flaws Enabling Authentication Bypass and VM Escape

Broadcom has released emergency security updates to fix multiple vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion, including three critical security flaws that could enable authentication bypass, remote code execution, and virtual machine escape attacks.

The company has urged organizations to apply the patches immediately, warning that no workarounds are available for the affected vulnerabilities.

Critical VMware vCenter Vulnerabilities Fixed

Among the most severe issues is CVE-2026-59309, a critical authentication bypass vulnerability with a CVSS score of 9.8.

According to Broadcom, an attacker with network access to a vulnerable VMware vCenter instance could exploit the flaw to bypass authentication and gain unauthorized access to the management platform.

Another critical vulnerability, CVE-2026-59310 (CVSS 9.8), affects VMware vCenter and allows attackers to perform a directory traversal attack that can lead to remote code execution (RCE).

If successfully exploited, the flaw enables attackers with network access to execute arbitrary code on the targeted system, posing a significant risk to enterprise virtualization environments.

Affected Products and Fixed Versions

Broadcom has released security updates for the following products:

  • VMware Cloud Foundation and VMware vSphere Foundation 9.1.x – Fixed in 9.1.0.0300
  • VMware Cloud Foundation and VMware vSphere Foundation 9.0.x – Fixed in 9.0.2.0100
  • VMware vCenter 8.0 – Fixed in 8.0 Update 3k
  • VMware Cloud Foundation 5.x – Patched through an asynchronous update to vCenter 8.0 Update 3k

Organizations using these versions are strongly encouraged to install the latest updates as soon as possible.

Virtual Machine Escape Vulnerability Also Patched

Broadcom also addressed CVE-2026-47876, a critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.

With a CVSS score of 9.3, the flaw could allow an attacker with local administrator privileges inside a virtual machine to execute code directly on the underlying ESX host.

This type of attack, commonly known as a virtual machine escape, enables malicious code to break out of an isolated guest virtual machine and compromise the physical host running it.

The vulnerability has been fixed in updated releases of VMware ESX, VMware Cloud Foundation, and VMware vSphere Foundation.

Additional Vulnerabilities Resolved

Broadcom’s latest security release also fixes two other vulnerabilities affecting VMware products.

CVE-2026-41703 – Information Disclosure and Denial of Service

This vulnerability, assigned a CVSS score of 7.6, is an out-of-bounds read issue affecting VMware ESX.

An attacker with virtual machine deployment privileges could exploit the flaw to trigger:

  • Information disclosure
  • Denial-of-Service (DoS)

On VMware Workstation and VMware Fusion, the impact is limited to information disclosure.

The issue has been resolved in updated versions of VMware ESX, Workstation 26H1, Fusion 26H1, VMware Cloud Foundation, and VMware vSphere Foundation.

CVE-2026-41709 – Insufficient Logging

Broadcom also patched CVE-2026-41709, a low-severity vulnerability with a CVSS score of 2.7.

The flaw allows a malicious administrator to perform specific operations without generating audit logs, potentially reducing visibility into administrative activity during forensic investigations.

Although rated lower in severity, organizations should still apply the available security updates to maintain complete audit trails.

No Active Exploitation Reported

Broadcom stated that it has not observed any evidence of active exploitation of these vulnerabilities in real-world attacks.

However, because there are no available mitigations or workarounds, the company has classified the updates as an emergency change and recommends immediate patching to reduce exposure.

Why Organizations Should Patch Immediately

VMware infrastructure often serves as the foundation of enterprise data centers and cloud environments, making vulnerabilities in virtualization software particularly attractive to attackers.

Authentication bypass, remote code execution, and virtual machine escape flaws can allow threat actors to compromise management servers, gain elevated privileges, and potentially access multiple virtual machines hosted within an organization’s infrastructure.

Applying Broadcom’s latest security updates is the most effective way to protect VMware deployments against these high-impact vulnerabilities.

Key Takeaways

Broadcom’s latest security advisory addresses several high-risk vulnerabilities across VMware products, including critical flaws that could enable authentication bypass, remote code execution, and virtual machine escape attacks.

While there are currently no reports of active exploitation, organizations should treat these updates as a priority. With no temporary mitigations available, timely patching remains essential to securing VMware environments against potential attacks.

Leave a Reply

Your email address will not be published. Required fields are marked *