Published on July 31, 2026

Broadcom Releases Emergency Security Updates for Critical VMware Authentication Bypass and VM Escape Vulnerabilities


Severity

Critical

Detail

Broadcom has released emergency security updates to address five vulnerabilities affecting VMware products, including three critical flaws that could allow attackers to bypass authentication, execute arbitrary code, or escape from a guest virtual machine (VM) to the underlying ESX host.

The most severe vulnerabilities affect VMware vCenter Server and VMware ESX. The first vulnerability, CVE-2026-59309, is an authentication bypass flaw in the VMware Directory Service that allows an unauthenticated attacker with network access to vCenter to gain unauthorized access. The second, CVE-2026-59310, is a directory traversal vulnerability in the vCenter Syslog service that enables unauthenticated remote attackers to execute arbitrary code through specially crafted requests.

A third critical vulnerability, CVE-2026-47876, affects the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using the VMXNET3 adapter can exploit an out-of-bounds write vulnerability to execute code on the ESX host, resulting in a virtual machine escape.

Broadcom also addressed two additional vulnerabilities, CVE-2026-41703, an out-of-bounds read vulnerability that may allow information disclosure or denial of service and CVE-2026-41709, an insufficient logging vulnerability that could enable malicious ESX administrators to perform operations without proper audit logging.

The vulnerabilities also impact products containing VMware vCenter or ESX components, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Broadcom has confirmed that there are no workarounds for these vulnerabilities and recommends organizations apply the security updates immediately. While there is currently no evidence of active exploitation in the wild, Broadcom considers these vulnerabilities emergency fixes due to the high risk they pose to enterprise virtualization environments.

CVE IDSummaryCVSS Score
CVE-2026-59309Authentication bypass vulnerability in VMware Directory Service allowing unauthenticated remote attackers to gain unauthorized access to VMware vCenter.9.8 (Critical)
CVE-2026-59310An authentication bypass vulnerability in Cisco Secure FMC Software allows unauthenticated remote attackers to execute scripts and commands as root through crafted HTTP requests.9.8 (Critical)
CVE-2026-47876Out-of-bounds write vulnerability in the VMXNET3 virtual network adapter allowing attackers to escape from a guest VM and execute code on the ESX host.9.3 (Critical)
CVE-2026-41703Out-of-bounds read vulnerability that may lead to information disclosure or denial of service.7.6 (Important – ESX) / 2.7 (Low – Workstation/Fusion)
CVE-2026-41709Insufficient logging vulnerability allowing certain administrator actions to occur without being logged.2.7 (Low)

Affected Products

The vulnerabilities affect the following:

  • VMware vCenter Server releases prior to 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k.
  • VMware ESX / ESXi releases prior to 9.1.0.0200, 9.0.2.0100, and 8.0 Update 3k.
  • VMware Workstation and VMware Fusion 25H2 (upgrade to 26H1 required to remediate CVE-2026-41703).
  • VMware Cloud Foundation deployments containing affected VMware vCenter or ESX/ESXi components.
  • VMware vSphere Foundation deployments containing affected VMware vCenter or ESX/ESXi components.
  • VMware Telco Cloud Platform deployments containing affected VMware vCenter or ESX/ESXi components.
  • VMware Telco Cloud Infrastructure deployments containing affected VMware vCenter or ESX/ESXi components.

Recommendation

Organizations should implement the following measures to reduce the risk of exploitation:

  • Apply the latest Broadcom security updates for all affected VMware products immediately.
  • Upgrade VMware vCenter, ESXi, Workstation, and Fusion to the fixed versions specified in Broadcom’s advisory.
  • Follow Broadcom’s product-specific patching guidance for VMware Cloud Foundation and VMware Telco products.
  • Use vMotion to migrate virtual machines before applying ESXi updates and perform rolling reboots where applicable.
  • Utilize ESX Live Patch where supported to minimize service disruption.
  • Review virtualization infrastructure for unauthorized access, suspicious administrative activity, and abnormal virtual machine behavior.
  • Verify upgrade compatibility for VMware Cloud Foundation environments before deploying the latest patches.

Source

https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017