Broadcom has issued emergency security updates for VMware, patching five vulnerabilities across vCenter Server, ESXi, Workstation and Fusion. Three of the flaws are rated critical, and no workarounds are available for the two vCenter issues — forcing every enterprise running the platform onto a fast patching path.
vCenter authentication bypass carries CVSS 9.8
The most severe issue, tracked as CVE-2026-59309, is an authentication bypass in the VMware Directory Service. A remote, unauthenticated attacker with network access to a vulnerable vCenter Server can bypass authentication and gain unauthorized control over the management platform, giving them the ability to reach every virtual machine attached to it. A second vCenter flaw, CVE-2026-59310, is a directory-traversal bug in the vCenter Syslog server that permits arbitrary code execution and also scores 9.8 on the CVSS v3 scale.
ESXi VM escape via VMXNET3
The third critical bug, CVE-2026-47876, is a virtual-machine escape flaw in the VMXNET3 virtual network adapter with a CVSS v3 base score of 9.3. An attacker with administrator privileges inside a guest VM can execute arbitrary code on the underlying ESXi host, potentially breaking the tenant boundary that private-cloud and multi-tenant hosting providers depend on. Broadcom said the two lower-severity issues span Workstation and Fusion.
Patch pressure for enterprises and hyperscalers
The advisory arrives on the heels of a run of high-profile enterprise infrastructure bugs, including a critical RCE in JetBrains TeamCity and Microsoft's MAI-Cyber-1 launch to speed defender response. Because vSphere still underpins most private-cloud and AI-training data centers, security teams are being told to prioritise vCenter and ESXi patching immediately. Broadcom's own expanding role in AI infrastructure has made VMware a more attractive target than ever.
Reporting based on coverage from Broadcom, The Hacker News, SecurityWeek and Qualys ThreatPROTECT.
