Connect with us

Cybersecurity

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Published

on

Broadcom has released emergency security updates to address multiple vulnerabilities affecting VMware products, including vCenter Server, ESXi, Workstation, and Fusion. Three of the vulnerabilities have been classified as critical, with the most severe flaws potentially allowing attackers to bypass authentication, execute arbitrary code, or escape from virtual machines to the underlying host system.

The security issues affect enterprise virtualization environments widely used by organizations to manage cloud infrastructure and virtual workloads. Broadcom has urged administrators to apply the available patches immediately because no temporary workarounds are available.

Critical vCenter Flaws Could Allow Unauthorized System Access

The most serious vulnerabilities affect VMware vCenter Server.

The first issue, tracked as CVE-2026-59309 with a CVSS score of 9.8, is an authentication bypass vulnerability. An attacker with network access to a vulnerable vCenter system could exploit the flaw to bypass authentication protections and gain unauthorized access.

The second critical issue, CVE-2026-59310, also rated 9.8, is a directory traversal vulnerability. Attackers with network access could exploit the weakness to execute arbitrary code on affected systems.

Broadcom has released fixes for these vulnerabilities in several VMware product versions, including:

  • VMware Cloud Foundation and VMware vSphere Foundation 9.1.x.x — fixed in version 9.1.0.0300
  • VMware Cloud Foundation and VMware vSphere Foundation 9.0.x.x — fixed in version 9.0.2.0100
  • VMware vCenter Server 8.0 — fixed in 8.0 U3k
  • VMware Cloud Foundation 5.x — fixed through an asynchronous patch to 8.0 U3k

VMware ESXi Flaw Could Enable Virtual Machine Escape

Another critical vulnerability, CVE-2026-47876, carries a CVSS score of 9.3 and affects the VMXNET3 virtual network adapter used by VMware ESXi.

The flaw is caused by an out-of-bounds write issue that could allow an attacker with local administrative privileges inside a virtual machine to execute code on the ESXi host.

This type of attack, known as a virtual machine escape, is considered highly serious because it allows an attacker to move beyond the isolated guest environment and potentially compromise the host infrastructure.

Broadcom has addressed the issue in updated ESXi releases, including:

  • ESXi-9.1.0.0200-25557999
  • ESXi-9.0.2.0100-25595025
  • ESXi80U3k-25595708

Additional VMware Security Issues Fixed

Broadcom also released patches for several additional vulnerabilities affecting VMware products.

CVE-2026-41703 — Information Disclosure and Denial-of-Service Risk

This vulnerability involves an out-of-bounds read issue in VMware ESX. Attackers with virtual machine deployment privileges could exploit it to access sensitive information or potentially trigger denial-of-service conditions.

On VMware Workstation and Fusion, the impact is limited to information disclosure.

CVE-2026-41709 — Insufficient Logging Issue

A lower-severity vulnerability affecting VMware ESX could allow a malicious administrator to perform certain actions without those operations being properly recorded in system logs.

The flaw has a CVSS score of 2.7 and has been fixed through updated VMware releases.

No Confirmed Exploitation Reported

Broadcom said it has not identified evidence that these vulnerabilities have been exploited in real-world attacks. However, the company classified the updates as emergency changes due to the potential impact and lack of available workarounds.

Organizations using VMware infrastructure are advised to review affected systems, prioritize patch deployment, and monitor environments for unusual activity.

Enterprise Virtualization Security Remains a Priority

The latest VMware security fixes highlight the importance of maintaining strong security controls in virtualized environments. Because virtualization platforms often manage critical workloads, vulnerabilities affecting hypervisors and management systems can have significant consequences.

Administrators should ensure that management interfaces are properly protected, access controls are regularly reviewed, and security updates are applied promptly to reduce exposure.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO