Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom released security updates for multiple VMware products addressing three critical vulnerabilities including authentication bypass, code execution, and virtual machine escape.

Through the Reader lens — Broadcom has issued emergency security patches for seven critical vulnerabilities affecting VMware vCenter, ESXi, Workstation, and Fusion, with a CVSS score of 9.8. The most severe flaw, CVE-2026-59310, is a directory traversal vulnerability in vCenter's Syslog server that allows remote code execution and is already being actively exploited in the wild, according to CISA's Known Exploited Vulnerabilities catalog. Additional critical issues include an authentication bypass in vCenter's Directory Service (CVE-2026-59309), an out-of-bounds write in ESXi's VMXNET3 adapter that could enable VM escape (CVE-2026-47876), and insufficient logging flaws that could allow malicious administrators to hide their activities. The vulnerabilities affect current versions of VMware Cloud Foundation, vSphere Foundation, and client applications. Organizations must apply patches immediately as the active exploitation of CVE-2026-59310 indicates attackers are already leveraging these flaws to compromise VMware infrastructure.
