Broadcom Patches Three Critical VMware Flaws, Including vCenter Auth Bypass And ESXi VM Escape

Broadcom's VMSA-2026-0006 advisory patches five flaws across vCenter, ESXi, Workstation and Fusion. Three are rated critical, including a CVSS 9.8 vCenter authentication bypass and a VMXNET3 VM escape that hits the entire enterprise install base.

Broadcom Patches Three Critical VMware Flaws, Including vCenter Auth Bypass And ESXi VM Escape

Broadcom has issued emergency security updates for VMware, patching five vulnerabilities across vCenter Server, ESXi, Workstation and Fusion. Three of the flaws are rated critical, and no workarounds are available for the two vCenter issues — forcing every enterprise running the platform onto a fast patching path.

vCenter authentication bypass carries CVSS 9.8

The most severe issue, tracked as CVE-2026-59309, is an authentication bypass in the VMware Directory Service. A remote, unauthenticated attacker with network access to a vulnerable vCenter Server can bypass authentication and gain unauthorized control over the management platform, giving them the ability to reach every virtual machine attached to it. A second vCenter flaw, CVE-2026-59310, is a directory-traversal bug in the vCenter Syslog server that permits arbitrary code execution and also scores 9.8 on the CVSS v3 scale.

ESXi VM escape via VMXNET3

The third critical bug, CVE-2026-47876, is a virtual-machine escape flaw in the VMXNET3 virtual network adapter with a CVSS v3 base score of 9.3. An attacker with administrator privileges inside a guest VM can execute arbitrary code on the underlying ESXi host, potentially breaking the tenant boundary that private-cloud and multi-tenant hosting providers depend on. Broadcom said the two lower-severity issues span Workstation and Fusion.

VMware logo

Patch pressure for enterprises and hyperscalers

The advisory arrives on the heels of a run of high-profile enterprise infrastructure bugs, including a critical RCE in JetBrains TeamCity and Microsoft's MAI-Cyber-1 launch to speed defender response. Because vSphere still underpins most private-cloud and AI-training data centers, security teams are being told to prioritise vCenter and ESXi patching immediately. Broadcom's own expanding role in AI infrastructure has made VMware a more attractive target than ever.

Reporting based on coverage from Broadcom, The Hacker News, SecurityWeek and Qualys ThreatPROTECT.

Category: Cyber Security

Tags: Cybersecurity AI Infrastructure Zero-Day CVE ransomware

Related Articles