Critical

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker News

Overview

Broadcom has issued security updates to fix several vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Among these, three flaws are deemed critical, with CVE-2026-59309 being the most severe, rated at 9.8 on the CVSS scale. This particular flaw allows attackers with network access to VMware vCenter to bypass authentication, potentially leading to unauthorized access. Other vulnerabilities could enable code execution and VM escape, which poses significant risks for virtualized environments. Organizations using these VMware products should prioritize applying the updates to safeguard against potential exploits.

Key Takeaways

  • Affected Systems: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion
  • Action Required: Users should apply the latest security updates provided by Broadcom for VMware ESX, vCenter, Workstation, and Fusion to mitigate these vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter

Impact

VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should apply the latest security updates provided by Broadcom for VMware ESX, vCenter, Workstation, and Fusion to mitigate these vulnerabilities.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, VMware, Vulnerability, and 1 more.

Related Coverage

CISA warns of Chinese "BrickStorm" malware attacks on VMware servers

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a new malware threat named BrickStorm, which is being used by Chinese hackers to backdoor VMware vSphere servers. This poses a significant risk to organizations using these servers, as it could lead to unauthorized access and potential data breaches.

Dec 4, 2025

VMware ESXi zero-days likely exploited a year before disclosure

BleepingComputer

Cybersecurity researchers have uncovered that a group of Chinese-speaking hackers exploited vulnerabilities in VMware ESXi, using a compromised SonicWall VPN appliance to deploy an exploit toolkit. This toolkit appears to have been created over a year before the vulnerabilities were publicly disclosed. This means that the attackers had access to these exploits long before companies were aware of their existence, potentially allowing them to infiltrate networks unnoticed. Organizations using VMware ESXi should be particularly vigilant, as the vulnerabilities could lead to significant security breaches. The incident underscores the need for companies to regularly update their systems and monitor for unusual activity, as these types of attacks can have serious implications for data security.

Jan 8, 2026

2024 VMware Flaw Now in Attackers’ Crosshairs

SecurityWeek

A newly discovered vulnerability in VMware products allows attackers to execute remote code by sending specially crafted network packets. This critical-severity flaw poses a serious risk for organizations using affected VMware systems, as it could lead to unauthorized access and control over their networks. VMware has not specified which products are impacted, but the nature of the vulnerability suggests that any systems relying on VMware technologies could be at risk. Companies should prioritize patching their systems as soon as updates are available to prevent potential exploitation. The urgency is heightened as this vulnerability is now a target for attackers.

Jan 26, 2026

CISA: VMware ESXi flaw now exploited in ransomware attacks

BleepingComputer

CISA has reported that ransomware gangs are now exploiting a serious vulnerability in VMware ESXi, which allows attackers to escape sandboxes and gain unauthorized access to systems. This vulnerability, which had previously been used in zero-day attacks, poses a significant risk to organizations using affected VMware products. Companies relying on VMware ESXi for virtualization need to be particularly vigilant, as attackers are actively targeting this flaw. The exploitation of such vulnerabilities can lead to severe data breaches and financial losses. Organizations should prioritize patching their systems to mitigate this risk and protect sensitive data from potential ransomware attacks.

Feb 4, 2026

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

SecurityWeek

VMware has patched seven serious vulnerabilities in its Avi Load Balancer that could allow attackers to bypass authentication, execute remote code, escalate privileges, and traverse directories. These vulnerabilities pose a significant risk to organizations relying on this load balancing technology, as they could lead to unauthorized access and control over systems. Users of VMware Avi Load Balancer should prioritize applying the latest patches to safeguard their environments. The severity of these vulnerabilities highlights the ongoing need for vigilance in cybersecurity practices, especially for widely used infrastructure components.

Jul 14, 2026

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

The Hacker News

Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.

Jul 15, 2026