CVE Tools

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker NewsBy The Hacker News

PatchESXivCenter

Our summary

Broadcom has issued security updates addressing several critical vulnerabilities in VMware products including vCenter, ESX, Workstation, and Fusion. Among them are two high-severity flaws—CVE-2026-59309 (authentication bypass) and CVE-2026-59310 (directory traversal)—that could allow remote attackers to gain unauthorized access or execute arbitrary code. Another notable flaw, CVE-2026-47876, enables local users to break out of a virtual machine and run code on the host system. Broadcom reports no evidence of real-world exploitation but urges administrators to apply patches immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store