Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Overview
Broadcom has issued security updates to fix several vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Among these, three flaws are deemed critical, with CVE-2026-59309 being the most severe, rated at 9.8 on the CVSS scale. This particular flaw allows attackers with network access to VMware vCenter to bypass authentication, potentially leading to unauthorized access. Other vulnerabilities could enable code execution and VM escape, which poses significant risks for virtualized environments. Organizations using these VMware products should prioritize applying the updates to safeguard against potential exploits.
Key Takeaways
- Affected Systems: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion
- Action Required: Users should apply the latest security updates provided by Broadcom for VMware ESX, vCenter, Workstation, and Fusion to mitigate these vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter
Impact
VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should apply the latest security updates provided by Broadcom for VMware ESX, vCenter, Workstation, and Fusion to mitigate these vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, VMware, Vulnerability, and 1 more.