Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

VMware fixes three critical flaws allowing auth bypass, VM escapes

0
Critical
Vulnerability
Published: 07/30/2026 (07/30/2026, 18:00:51 UTC)
Source: Bleeping Computer

Description

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

Affected software

Affected versions
>=9.0.2.0100 <9.0.2.0101>=9.1.0.0200 <9.1.0.0201>=9.1.0.0300 <9.1.0.0301

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 18:07:20 UTC

Technical Analysis

Five vulnerabilities were fixed by Broadcom in VMware vCenter, ESX, Workstation, and Fusion, including three critical ones: CVE-2026-59309 (authentication bypass in VMware Directory Service), CVE-2026-59310 (directory traversal and arbitrary code execution in vCenter Syslog server), and CVE-2026-47876 (out-of-bounds write in VMXNET3 adapter allowing VM escape). These critical flaws have CVSS scores of 9.8 and 9.3 respectively. Additional vulnerabilities include an out-of-bounds read (CVE-2026-41703) causing information disclosure or denial-of-service and an insufficient logging issue (CVE-2026-41709). Fixed versions are provided for vCenter (9.1.0.0300, 9.0.2.0100, 8.0 Update 3k), ESX (ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k), and Workstation/Fusion (upgrade from 25H2 to 26H1). No workarounds exist, and switching away from VMXNET3 is discouraged. Patching may cause temporary service interruptions and requires careful operational planning. No exploitation in the wild has been reported, but VMware servers are common targets for attackers.

Potential Impact

Successful exploitation of the critical vulnerabilities can lead to unauthorized authentication bypass, remote code execution on vCenter servers, and virtual machine escape to the ESX host, potentially compromising the entire virtualization infrastructure. Other vulnerabilities may cause information disclosure, denial-of-service, or insufficient logging of malicious administrator actions. These impacts threaten confidentiality, integrity, and availability of VMware environments and the data they host.

Mitigation Recommendations

Official security updates are available and should be applied immediately as emergency changes. Fixed versions include vCenter 9.1.0.0300, 9.0.2.0100, 8.0 Update 3k; ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k; and Workstation/Fusion 26H1. There are no workarounds. Administrators should plan for temporary service interruptions during patching, including vCenter management interface downtime and ESX host restarts. Use vMotion to migrate virtual machines during ESX updates to minimize disruption. ESX Live Patch can reduce downtime but is not applicable to vCenter updates. Avoid switching virtual network adapters away from VMXNET3 due to performance and security considerations. Check Broadcom's advisory for detailed patching instructions and compatibility notes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","fetched":true,"fetchedAt":"2026-07-30T18:07:07.218Z","wordCount":1165}

Threat ID: 6a6b92cb9c2644c7f8777ca3

Added to database: 07/30/2026, 18:07:07 UTC

Last enriched: 07/30/2026, 18:07:20 UTC

Last updated: 07/31/2026, 01:40:12 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses