Skip to content

Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape

Share
Source: Badtech.org

Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical.

They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication bypass rated CVSS 9.8, and that Broadcom also fixed CVE-2026-59310, a critical directory traversal flaw in the Syslog Server component that can lead to remote code execution over the network. vCenter is VMware’s centralized management platform for ESXi hosts and virtual machines.

The same reporting said Broadcom patched CVE-2026-47876, a critical flaw in the ESXi VMXNET3 virtual network adapter that could let an attacker with administrative privileges inside a guest VM execute code on the ESXi host. That creates a guest-to-host escalation path in shared infrastructure. Security Affairs and Mallory.ai said Broadcom was not aware of in-the-wild exploitation and urged customers to apply updates.

Sources