← Back to feed
cybersecurityCVSS 9.8 critical⚠ Actively exploitedCVE-2026-59309CVE-2026-59310CVE-2026-478768 sources · 8d ago

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom released security updates for multiple VMware products addressing three critical vulnerabilities including authentication bypass, code execution, and virtual machine escape.

AffectedUnited States Vmware VMware Fusion VMware vCenter VMware Workstation Broadcom Tencent Xuanwu Lab Tianchu Chen Yeonghyeon Choi
8 outlets · 2 origins · Balanced
United States × 6India × 2

Through the Reader lens — Broadcom has issued emergency security patches for seven critical vulnerabilities affecting VMware vCenter, ESXi, Workstation, and Fusion, with a CVSS score of 9.8. The most severe flaw, CVE-2026-59310, is a directory traversal vulnerability in vCenter's Syslog server that allows remote code execution and is already being actively exploited in the wild, according to CISA's Known Exploited Vulnerabilities catalog. Additional critical issues include an authentication bypass in vCenter's Directory Service (CVE-2026-59309), an out-of-bounds write in ESXi's VMXNET3 adapter that could enable VM escape (CVE-2026-47876), and insufficient logging flaws that could allow malicious administrators to hide their activities. The vulnerabilities affect current versions of VMware Cloud Foundation, vSphere Foundation, and client applications. Organizations must apply patches immediately as the active exploitation of CVE-2026-59310 indicates attackers are already leveraging these flaws to compromise VMware infrastructure.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Broadcom / VMwareUnited StatesPatching critical vulnerabilities across VMware product suite

Broadcom has released emergency security updates for VMware vCenter, ESXi, Workstation, and Fusion to address multiple critical vulnerabilities including authentication bypass, code execution, and VM escape flaws.

CISA / Vulnerability DisclosersUnited StatesWarning of active exploitation and urging immediate patching

CISA has added CVE-2026-59310 (vCenter directory traversal leading to arbitrary code execution) to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild.

Neutral reportingReporting on vulnerability details and patch availability

Technical reporting covers the disclosure of seven CVEs affecting VMware infrastructure, with CVSS 9.8 severity, including out-of-bounds read/write, directory traversal, authentication bypass, and insufficient logging vulnerabilities.

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • VMware vCenter Server remote code execution · immediate
  • VMware ESXi hosts vm escape · immediate
  • Organizations using VMware infrastructure patch required · days
  • VMware vCenter authentication authentication bypass · immediate

Sources (8)

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape — Prism