Broadcom fixes two critical vulnerabilities in VMware vCenter that allow server takeover without authentication

Broadcom has released one of the most significant security updates of the year for the VMware ecosystem. The company has patched five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion, including two critical flaws with CVSS scores of 9.8 that could allow a remote attacker to bypass vCenter authentication or execute arbitrary code. There are no workarounds available, so Broadcom recommends installing the patches as soon as possible.

A quick summary of VMware vulnerabilities in 30 seconds

  • Broadcom patches five vulnerabilities in vCenter, ESX, Workstation, and Fusion.
  • Two critical flaws (CVSS 9.8) allow remote compromise of vCenter.
  • No temporary solutions: the only protection is to install the updates.
  • A third critical vulnerability affects ESX and could allow escape from a virtual machine to the host under certain conditions.
  • Security updates are also provided for VMware Cloud Foundation and vSphere Foundation.

The vulnerabilities are published under the advisory VMSA-2026-0006, affecting nearly Broadcom’s entire virtualization product line. While some require prior privileges or impact specific scenarios, the two vCenter-related issues are the most concerning due to their potential impact on VMware management infrastructure.

The greatest risk lies in vCenter

The first vulnerability, CVE-2026-59309, affects the VMware Directory Service and introduces a bypass authentication flaw.

According to Broadcom, an attacker with network access to the server could exploit this flaw to circumvent normal authentication and gain unauthorized access to the system.

The company assigns it a CVSS score of 9.8, the highest within this bulletin.

The second critical vulnerability, CVE-2026-59310, affects the vCenter Syslog server.

It involves a directory traversal flaw that could allow arbitrary code execution with a CVSS score of 9.8.

In both cases, Broadcom confirms that no workarounds are available.

The only recommended measure is to install the patched versions of vCenter.

For currently supported releases, the versions including fixes are:

  • vCenter 9.1.0.0300
  • vCenter 9.0.2.0100
  • vCenter 8.0 U3k

Customers using VMware Cloud Foundation 5.x should apply the corresponding asynchronous patch, and Telco Cloud platforms have specific updates available through KB449886.

A vulnerability in ESX could allow VM escape

The third significant issue is CVE-2026-47876.

It affects the widely used virtual network adapter VMXNET3 in VMware virtual machines.

Broadcom describes an out-of-bounds write vulnerability with a CVSS score of 9.3.

Unlike the vCenter flaws, this vulnerability cannot be exploited remotely from the internet.

An attacker would need prior administrative privileges within a VM using VMXNET3.

Under those conditions, it could potentially execute code on the ESX host, breaking the virtual machine-to-hypervisor isolation.

This type of vulnerability is especially critical for cloud providers and multi-tenant environments, where hypervisor-based isolation is key to tenant separation.

VMs using other virtual network adapters are unaffected.

Broadcom addresses this vulnerability with patches for:

  • ESXi 9.1.0.0200
  • ESXi 9.0.2.0100
  • ESXi 8.0 U3k

Updates also available for Workstation and Fusion

The bulletin also mentions two lower-severity vulnerabilities.

The first, CVE-2026-41703, involves an out-of-bounds read.

In ESX, this could cause a denial of service or information disclosure under certain conditions.

In Workstation and Fusion, the impact is limited to potential info leaks.

Severity levels vary by product:

  • CVSS 7.6 on ESX
  • CVSS 2.7 on Workstation and Fusion

Patch versions are:

  • Workstation 26H1
  • Fusion 26H1

The final vulnerability, CVE-2026-41709, affects ESX’s event log system.

Broadcom calls it an insufficient logging vulnerability with a CVSS score of 2.7.

It could allow an administrator to perform certain actions that aren’t properly recorded in audit logs.

While it doesn’t provide a direct way to compromise the system, it can hinder forensic investigations or regulatory compliance efforts.

Are there active exploits?

Broadcom does not indicate that these vulnerabilities are actively exploited in the wild.

The flaws were disclosed via responsible disclosure.

The two critical vCenter issues were reported by Phil Brass and Matt South from Atredis Partners.

The VMXNET3 flaw was discovered by Nguyen Hoang Thach of STARLabs SG during the Pwn2Own competition organized by the Zero Day Initiative.

This indicates that researchers managed to demonstrate the exploit in a controlled environment before Broadcom’s announcement.

As with many critical vulnerabilities in widely used platforms, public proof-of-concept code is likely to appear once patches are released.

Why are these vulnerabilities especially critical?

In many organizations, vCenter is the brain of the entire VMware infrastructure.

It manages:

  • ESXi hosts;
  • Virtual machines;
  • Virtual networks;
  • Storage;
  • Permissions;
  • HA clusters;
  • vMotion;
  • Built-in backups.

Compromising vCenter can give full control over the virtual environment.

In cloud providers and large data centers, the potential impact could extend to hundreds or thousands of VMs.

The VMXNET3 vulnerability is especially noteworthy because it affects one of VMware’s most widely used components.

Although it requires admin privileges within a VM, an escape flaw that lets an attacker break out to the host is highly prioritized in virtualization security.

Recommendations for administrators now

Since no temporary mitigations are available, the priority is to update all affected components promptly.

Before deploying patches, it is advisable to:

  • Identify all deployed vCenter and ESXi versions;
  • Check for any secondary management servers;
  • Review maintenance windows;
  • Verify backups of vCenter;
  • Update management systems first, followed by hosts where applicable;
  • Validate that HA, DRS, vMotion, and monitoring tools are functioning correctly afterward.

Admins of VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms should also consult the specific version matrix published by Broadcom to apply the correct patch for their environment.

While the bulletin includes lower-severity vulnerabilities, the two issues affecting vCenter make this update a top priority for any organization using VMware virtualization this year.

Frequently Asked Questions

What is the most critical vulnerability?

The two vCenter vulnerabilities (CVE-2026-59309 and CVE-2026-59310) are rated CVSS 9.8 and respectively allow authentication bypass and remote arbitrary code execution.

Are there any workarounds?

No. Broadcom explicitly states that no workarounds exist for these critical vulnerabilities. The only solution is to install the patches.

Can the ESX vulnerability be exploited remotely?

Not directly. CVE-2026-47876 requires administrative privileges inside a VM using VMXNET3.

Which products are affected?

The advisory impacts VMware ESX, vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Sources:

Scroll to Top