Broadcom has released emergency security updates to address multiple vulnerabilities affecting VMware products, including vCenter Server, ESXi, Workstation, and Fusion. Three of the vulnerabilities have been classified as critical, with the most severe flaws potentially allowing attackers to bypass authentication, execute arbitrary code, or escape from virtual machines to the underlying host system.
The security issues affect enterprise virtualization environments widely used by organizations to manage cloud infrastructure and virtual workloads. Broadcom has urged administrators to apply the available patches immediately because no temporary workarounds are available.
Critical vCenter Flaws Could Allow Unauthorized System Access
The most serious vulnerabilities affect VMware vCenter Server.
The first issue, tracked as CVE-2026-59309 with a CVSS score of 9.8, is an authentication bypass vulnerability. An attacker with network access to a vulnerable vCenter system could exploit the flaw to bypass authentication protections and gain unauthorized access.
The second critical issue, CVE-2026-59310, also rated 9.8, is a directory traversal vulnerability. Attackers with network access could exploit the weakness to execute arbitrary code on affected systems.
Broadcom has released fixes for these vulnerabilities in several VMware product versions, including:
- VMware Cloud Foundation and VMware vSphere Foundation 9.1.x.x — fixed in version 9.1.0.0300
- VMware Cloud Foundation and VMware vSphere Foundation 9.0.x.x — fixed in version 9.0.2.0100
- VMware vCenter Server 8.0 — fixed in 8.0 U3k
- VMware Cloud Foundation 5.x — fixed through an asynchronous patch to 8.0 U3k
VMware ESXi Flaw Could Enable Virtual Machine Escape
Another critical vulnerability, CVE-2026-47876, carries a CVSS score of 9.3 and affects the VMXNET3 virtual network adapter used by VMware ESXi.
The flaw is caused by an out-of-bounds write issue that could allow an attacker with local administrative privileges inside a virtual machine to execute code on the ESXi host.
This type of attack, known as a virtual machine escape, is considered highly serious because it allows an attacker to move beyond the isolated guest environment and potentially compromise the host infrastructure.
Broadcom has addressed the issue in updated ESXi releases, including:
- ESXi-9.1.0.0200-25557999
- ESXi-9.0.2.0100-25595025
- ESXi80U3k-25595708
Additional VMware Security Issues Fixed
Broadcom also released patches for several additional vulnerabilities affecting VMware products.
CVE-2026-41703 — Information Disclosure and Denial-of-Service Risk
This vulnerability involves an out-of-bounds read issue in VMware ESX. Attackers with virtual machine deployment privileges could exploit it to access sensitive information or potentially trigger denial-of-service conditions.
On VMware Workstation and Fusion, the impact is limited to information disclosure.
CVE-2026-41709 — Insufficient Logging Issue
A lower-severity vulnerability affecting VMware ESX could allow a malicious administrator to perform certain actions without those operations being properly recorded in system logs.
The flaw has a CVSS score of 2.7 and has been fixed through updated VMware releases.
No Confirmed Exploitation Reported
Broadcom said it has not identified evidence that these vulnerabilities have been exploited in real-world attacks. However, the company classified the updates as emergency changes due to the potential impact and lack of available workarounds.
Organizations using VMware infrastructure are advised to review affected systems, prioritize patch deployment, and monitor environments for unusual activity.
Enterprise Virtualization Security Remains a Priority
The latest VMware security fixes highlight the importance of maintaining strong security controls in virtualized environments. Because virtualization platforms often manage critical workloads, vulnerabilities affecting hypervisors and management systems can have significant consequences.
Administrators should ensure that management interfaces are properly protected, access controls are regularly reviewed, and security updates are applied promptly to reduce exposure.