Broadcom has launched safety updates that repair 5 vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion. Three of the important flaws may permit an attacker to bypass authentication, execute arbitrary code, or escape from the digital machine to the host.
This vulnerability additionally impacts merchandise that embrace vCenter or ESX, similar to VMware Cloud Basis, VMware vSphere Basis, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
Broadcom says organizations working variations launched previous to these listed as fastened within the advisory ought to assume they’re weak and take rapid motion.
The 5 vulnerabilities are summarized under.
- CVE-2026-59309: A important authentication bypass vulnerability exists in VMware Listing Service. An unauthenticated attacker with community entry to vCenter may exploit this flaw to bypass authentication and achieve unauthorized entry to the system.
- CVE-2026-59310: A important listing traversal vulnerability within the vCenter Syslog server may permit an unauthenticated attacker to entry the community and execute arbitrary code.
- CVE-2026-47876: A important out-of-bounds write vulnerability exists within the VMXNET3 digital community adapter. An attacker with native administrative privileges inside a digital machine utilizing VMXNET3 may exploit this flaw to execute code on the ESX host and escape the digital machine. Digital machines utilizing different digital community adapters will not be affected.
- CVE-2026-41703: Out-of-bounds learn vulnerability in ESX, Workstation, and Fusion. An attacker with deployment privileges on the digital machine may exploit this to reveal info or trigger a denial of service situation within the host course of. For Workstation and Fusion, the impression is restricted to info disclosure.
- CVE-2026-41709: Inadequate logging may permit a malicious ESX administrator to carry out sure operations with out logging.
The three important vulnerabilities are two vCenter flaws, CVE-2026-59309 and CVE-2026-59310, with a CVSS rating of 9.8, and a VMXNET3 escape flaw, CVE-2026-47876, with a CVSS rating of 9.3.
The remaining points are much less extreme, with CVE-2026-41703 rated Vital on ESX with a rating of seven.6. For Workstation and Fusion, the impression is restricted to info disclosure and is rated as Low with a rating of two.7. CVE-2026-41709 can also be rated low at 2.7.
The vCenter vulnerability is fastened in variations 9.1.0.0300, 9.0.2.0100, and eight.0 Replace 3k, and the ESX flaw is resolved in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Replace 3k.
VMware Workstation and Fusion customers working model 25H2 ought to improve to 26H1 to deal with CVE-2026-41703. VMware Cloud Basis 5.x and affected service merchandise have separate patching directions within the Broadcom advisory.
Broadcom stated it doesn’t advocate switching digital machines away from the VMXNET3 adapter as a result of there isn’t a workaround for this vulnerability and different digital community adapters have safety flaws and will degrade efficiency.
Broadcom is treating these as emergency fixes and inspiring directors to put in them as quickly as attainable.
“These points qualify as emergency modifications below ITIL methodology and require rapid organizational motion,” Broadcom warned in a supplemental FAQ.
Nonetheless, because the service is at the moment being up to date, there could also be some impression.
In response to Broadcom, patching vCenter will briefly disrupt entry to the vSphere Shopper and different administration interfaces, however working digital machines and containers will proceed to work.
As a result of updating VMware ESX requires a server reboot, Broadcom recommends that directors use vMotion to maneuver digital machines to different hosts whereas the cluster is up to date with a rolling reboot. Digital machines that can not be migrated have to be powered off throughout reboot.
In supported environments, you can too use ESX Dwell Patch to cut back disruption, however vCenter updates will not be coated by Fast Patch.
Broadcom additionally warns that you could be encounter compatibility points when upgrading VMware Cloud Basis with new patches.
Sure, the “backward” limitation happens if a patch updates a product department that has a more recent construct quantity than the goal of the deliberate improve. ” explains the FAQ.
“vSphere 8.0 and 9.0 updates on this advisory block upgrades to VMware Cloud Basis 9.x and report a ‘backward’ error.
The corporate says improve compatibility will probably be restored in a future launch.
Broadcom says there isn’t a indication that the vulnerability on this advisory is being exploited within the wild.
Nonetheless, VMware servers are a standard goal for assaults as a result of a compromised VMware vCenter or ESXi server can present entry to a big portion of a corporation’s servers and the info saved on them.
For fairly a while, many ransomware gangs have created specialised encryption applications that particularly goal VMware digital machines which are frequent inside enterprises.
In December 2025, CISA additionally warned that Chinese language attackers had been compromising VMware vSphere servers to deploy BrickStorm malware, create hidden rogue digital machines, and steal snapshots of cloned digital machines for credential theft.
CrowdStrike has additionally noticed attackers utilizing the ESXi shell to create unregistered “ghost” digital machines that aren’t seen in ESXi or the vCenter net console. It is a persistence methodology that the corporate tracks as VirtualGHOST.
Broadcom just isn’t conscious of any exploits of the newly patched vulnerabilities, however directors ought to apply updates as quickly as attainable.

Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remainder strikes invisibly by means of the setting.
Picus’ whitepaper reveals methods to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
