VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
AI Analysis
Technical Summary
Five vulnerabilities were fixed by Broadcom in VMware vCenter, ESX, Workstation, and Fusion, including three critical ones: CVE-2026-59309 (authentication bypass in VMware Directory Service), CVE-2026-59310 (directory traversal and arbitrary code execution in vCenter Syslog server), and CVE-2026-47876 (out-of-bounds write in VMXNET3 adapter allowing VM escape). These critical flaws have CVSS scores of 9.8 and 9.3 respectively. Additional vulnerabilities include an out-of-bounds read (CVE-2026-41703) causing information disclosure or denial-of-service and an insufficient logging issue (CVE-2026-41709). Fixed versions are provided for vCenter (9.1.0.0300, 9.0.2.0100, 8.0 Update 3k), ESX (ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k), and Workstation/Fusion (upgrade from 25H2 to 26H1). No workarounds exist, and switching away from VMXNET3 is discouraged. Patching may cause temporary service interruptions and requires careful operational planning. No exploitation in the wild has been reported, but VMware servers are common targets for attackers.
Potential Impact
Successful exploitation of the critical vulnerabilities can lead to unauthorized authentication bypass, remote code execution on vCenter servers, and virtual machine escape to the ESX host, potentially compromising the entire virtualization infrastructure. Other vulnerabilities may cause information disclosure, denial-of-service, or insufficient logging of malicious administrator actions. These impacts threaten confidentiality, integrity, and availability of VMware environments and the data they host.
Mitigation Recommendations
Official security updates are available and should be applied immediately as emergency changes. Fixed versions include vCenter 9.1.0.0300, 9.0.2.0100, 8.0 Update 3k; ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k; and Workstation/Fusion 26H1. There are no workarounds. Administrators should plan for temporary service interruptions during patching, including vCenter management interface downtime and ESX host restarts. Use vMotion to migrate virtual machines during ESX updates to minimize disruption. ESX Live Patch can reduce downtime but is not applicable to vCenter updates. Avoid switching virtual network adapters away from VMXNET3 due to performance and security considerations. Check Broadcom's advisory for detailed patching instructions and compatibility notes.
VMware fixes three critical flaws allowing auth bypass, VM escapes
Description
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Five vulnerabilities were fixed by Broadcom in VMware vCenter, ESX, Workstation, and Fusion, including three critical ones: CVE-2026-59309 (authentication bypass in VMware Directory Service), CVE-2026-59310 (directory traversal and arbitrary code execution in vCenter Syslog server), and CVE-2026-47876 (out-of-bounds write in VMXNET3 adapter allowing VM escape). These critical flaws have CVSS scores of 9.8 and 9.3 respectively. Additional vulnerabilities include an out-of-bounds read (CVE-2026-41703) causing information disclosure or denial-of-service and an insufficient logging issue (CVE-2026-41709). Fixed versions are provided for vCenter (9.1.0.0300, 9.0.2.0100, 8.0 Update 3k), ESX (ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k), and Workstation/Fusion (upgrade from 25H2 to 26H1). No workarounds exist, and switching away from VMXNET3 is discouraged. Patching may cause temporary service interruptions and requires careful operational planning. No exploitation in the wild has been reported, but VMware servers are common targets for attackers.
Potential Impact
Successful exploitation of the critical vulnerabilities can lead to unauthorized authentication bypass, remote code execution on vCenter servers, and virtual machine escape to the ESX host, potentially compromising the entire virtualization infrastructure. Other vulnerabilities may cause information disclosure, denial-of-service, or insufficient logging of malicious administrator actions. These impacts threaten confidentiality, integrity, and availability of VMware environments and the data they host.
Mitigation Recommendations
Official security updates are available and should be applied immediately as emergency changes. Fixed versions include vCenter 9.1.0.0300, 9.0.2.0100, 8.0 Update 3k; ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k; and Workstation/Fusion 26H1. There are no workarounds. Administrators should plan for temporary service interruptions during patching, including vCenter management interface downtime and ESX host restarts. Use vMotion to migrate virtual machines during ESX updates to minimize disruption. ESX Live Patch can reduce downtime but is not applicable to vCenter updates. Avoid switching virtual network adapters away from VMXNET3 due to performance and security considerations. Check Broadcom's advisory for detailed patching instructions and compatibility notes.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","fetched":true,"fetchedAt":"2026-07-30T18:07:07.218Z","wordCount":1165}
Threat ID: 6a6b92cb9c2644c7f8777ca3
Added to database: 07/30/2026, 18:07:07 UTC
Last enriched: 07/30/2026, 18:07:20 UTC
Last updated: 07/31/2026, 01:40:12 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.