CVE Tools

VMware fixes three critical flaws allowing auth bypass, VM escapes

BleepingComputerBy Lawrence Abrams

PatchvCenterESX

Our summary

Broadcom has issued security updates addressing five vulnerabilities in VMware products, including three critical flaws that enable authentication bypass, remote code execution, and virtual machine escape. The most severe issues—CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876—affect vCenter and ESX systems, with CVSS scores up to 9.8. These flaws could allow unauthenticated attackers to gain unauthorized access or escalate privileges to the host system. Affected products include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms. Broadcom urges immediate patching, noting no workarounds are available and that delays could expose infrastructure to potential attacks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store