A trio of critical vulnerabilities has been patched by Broadcom in its recent security update for VMware products. These flaws, present in various versions of vCenter, ESX, Workstation, and Fusion, have the potential to grant unauthorized access to systems, allow malicious code execution, or even facilitate a virtual machine escape to the host.
The affected products include vCenter, ESX, Workstation, and Fusion, as well as other Broadcom offerings such as VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. Organisations running older versions of these products are urged by Broadcom to assume they are vulnerable and take immediate action.
One critical vulnerability, CVE-2026-59309, resides in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit this flaw to bypass authentication and gain unauthorized access to the system. Another critical issue, CVE-2026-59310, is a directory traversal vulnerability in the vCenter Syslog server that enables an unauthenticated attacker to execute arbitrary code.
The third critical flaw, CVE-2026-47876, is an out-of-bounds write vulnerability present in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit this flaw to execute code on the ESX host, resulting in a virtual machine escape. Virtual machines that use other virtual network adapters are not affected.
Additional vulnerabilities were also patched by Broadcom. CVE-2026-41703 is an out-of-bounds read vulnerability present in ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges can exploit this flaw to disclose information or cause a denial-of-service condition on the host process. On Workstation and Fusion, the impact of this issue is limited to information disclosure.
CVE-2026-41709 is an insufficient logging vulnerability that enables a malicious ESX administrator to perform certain operations without them being logged. This issue is rated as Low severity with a CVSS score of 2.7.
The three critical vulnerabilities have CVSS scores ranging from 9.3 to 9.8, making prompt action essential for organisations running vulnerable products. Broadcom has released emergency fixes for these issues and urges admins to install them immediately.
While there are no workarounds for the vulnerabilities, Broadcom cautions against switching virtual machines away from the VMXNET3 adapter due to potential security flaws in other virtual network adapters that may reduce performance. The updates will require downtime for services as they are updated, with vCenter temporarily interrupting access to the vSphere Client and other management interfaces.
To mitigate disruption, admins can use ESX Live Patch on supported environments or move virtual machines to other hosts while clusters are updated through a rolling reboot.
Source: Bleeping Computer — 2026-07-30