VMware fixes three critical flaws allowing auth bypass, VM escapes

VMware’s latest security patches have addressed five vulnerabilities across its product suite, including three critical flaws that enable attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine. The fixes are considered emergency updates by Broadcom, and admins are urged to apply them as soon as possible.

The affected products include VMware vCenter, ESX, Workstation, Fusion, and several other offerings that contain these components. Organizations running versions released before those listed in the advisory should assume they are vulnerable and take immediate action to protect themselves.

One of the critical vulnerabilities, CVE-2026-59309, is an authentication bypass flaw in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit this vulnerability to gain unauthorized access to the system. Similarly, CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker to execute arbitrary code.

The third critical vulnerability, CVE-2026-47876, affects VMXNET3 virtual network adapters and enables an attacker with local administrative privileges inside a virtual machine to execute code on the ESX host. This results in a virtual machine escape, where the attacker can gain access to the host system. Other virtual network adapters are not affected by this vulnerability.

In addition to these critical flaws, two other vulnerabilities were patched: CVE-2026-41703, an out-of-bounds read vulnerability that affects ESX, Workstation, and Fusion; and CVE-2026-41709, an insufficient logging vulnerability in ESX. While these issues are less severe than the critical ones, they still pose a risk to affected systems.

Broadcom has provided detailed instructions for applying the patches, including workarounds for potential disruptions to services during updates. Admins should note that patching vCenter temporarily interrupts access to the vSphere Client and other management interfaces, but running virtual machines and containers will continue operating. ESX updates require a server restart, so admins are advised to use vMotion to move virtual machines to other hosts while clusters are updated through a rolling reboot.

In some cases, administrators may encounter compatibility issues when upgrading VMware Cloud Foundation with the new patches. Broadcom warns that there may be a “back in time” restriction when applying patches that update a product branch carrying a newer build number than the target of a planned upgrade. This can block upgrades to VMware Cloud Foundation 9.x and result in an error message.

To protect themselves, administrators should review their environments and apply the necessary patches as soon as possible. By doing so, they will be able to mitigate these vulnerabilities and prevent potential attacks from occurring. As with any security update, it’s essential to carefully read through the instructions provided by Broadcom and plan accordingly for any potential disruptions to services during the patching process.

In practical terms, this means that administrators should prioritize applying the patches and ensure that their systems are up-to-date before they become vulnerable to these attacks. It’s also crucial to follow proper backup procedures and have a disaster recovery plan in place to minimize downtime and data loss in case of an emergency update.


Source: Bleeping Computer — 2026-07-30