TL;DR
Broadcom released patches for multiple critical flaws in VMware products. The most severe issue is a VMware authentication bypass in vCenter Server. Attackers can exploit this flaw to gain unauthorized system access. These vulnerabilities require immediate attention from system administrators.
Why It Matters
VMware solutions power countless enterprise networks worldwide. A compromise of vCenter Server grants broad control over virtualized environments. This VMware authentication bypass carries a critical CVSS base score of 9.8. Consequently, organizations face high risks of data breaches or ransomware deployments. The advisory confirms, “Updates are available to remediate these vulnerabilities in affected Broadcom products.” Broadcom indicates that these vulnerabilities were privately reported. The official advisory does not confirm any active exploitation in the wild. However, the critical nature of these flaws demands rapid patching. Delaying updates could leave core infrastructure exposed to opportunistic attacks.
How the Attack Works
The advisory details several distinct security mechanisms. First, CVE-2026-59309 resides in the VMware Directory Service. A network-based attacker sends crafted requests to bypass standard authentication checks. Second, CVE-2026-59310 involves a directory traversal flaw in the Syslog server. An attacker uses this to read or write unauthorized files. This can lead to arbitrary code execution on the affected system. Additionally, CVE-2026-47876 is an out-of-bounds write vulnerability. It affects the VMXNET3 virtual network adapter. A local attacker with administrative rights on a virtual machine can trigger this flaw. They can then execute code directly on the ESXi host. Next, CVE-2026-41703 involves an out-of-bounds read error. This could allow an attacker to cause a denial-of-service condition. Finally, CVE-2026-41709 is an insufficient logging vulnerability. This could allow a malicious administrator to perform certain operations without them being logged.
Affected Versions
These security flaws affect several key products across the VMware ecosystem. Impacted software includes VMware ESX, vCenter, Workstation, and Fusion. Furthermore, VMware Cloud Foundation and vSphere Foundation contain vulnerable components. Telco Cloud Platform and Telco Cloud Infrastructure are also affected. For vCenter specifically, versions 9.1.x.x, 9.0.x.x, and 8.0 require updates. The advisory notes that non-VMXNET3 virtual adapters are not affected by CVE-2026-47876.
Patch or Mitigation Steps
Administrators must apply the latest updates immediately. Broadcom strongly advises organizations to review the official security advisory for detailed patching matrices. To fix the critical vCenter flaws, update to version 9.1.0.0300, 9.0.2.0100, or 8.0 U3k. The advisory states, “Please note that patches are cumulative, meaning the current version includes all previously released fixes.” Currently, no workarounds exist for the critical vCenter vulnerabilities. Therefore, patching remains the only viable defense strategy. System administrators should prioritize vCenter updates due to their high severity scores. Afterward, teams should address the ESXi and Workstation patches to secure the entire virtual environment.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.