VMware Patches Critical Authentication Bypass Vulnerabilities

Broadcom has released critical security updates addressing multiple vulnerabilities in VMware’s core virtualization platforms, including vCenter Server, ESX, Workstation, Fusion, Cloud Foundation, and various Telco Cloud products. These flaws, if exploited, could allow attackers to bypass authentication mechanisms, execute arbitrary code, and escalate privileges, posing significant risks to enterprise environments.

Details of the Vulnerabilities

The most severe of these vulnerabilities is CVE-2026-59309, an authentication bypass issue in the VMware Directory Service utilized by vCenter Server. An attacker with network access to vCenter could exploit this flaw to gain unauthorized access to the management plane, potentially compromising the entire virtual infrastructure.

Another critical vulnerability, CVE-2026-59310, involves directory traversal in the vCenter Syslog server. By exploiting this flaw, a remote attacker with network access could execute arbitrary code, leading to further compromise within the data center.

Additionally, CVE-2026-47876 affects the VMXNET3 virtual network adapter in VMware ESX. This vulnerability allows a malicious actor with local administrative privileges inside a guest VM to execute code directly on the ESX host, effectively escaping the virtual machine boundary.

Impacted Products and Recommendations

The vulnerabilities impact a range of VMware products, including:

  • VMware ESX
  • vCenter Server
  • Workstation
  • Fusion
  • VMware Cloud Foundation
  • vSphere Foundation

Broadcom has provided patches for these vulnerabilities and strongly recommends that users apply the updates promptly to mitigate potential risks. The company has not reported any in-the-wild exploitation of these flaws at this time.

Given the critical nature of these vulnerabilities, organizations should prioritize updating their VMware environments to the latest versions. Failure to do so could leave systems exposed to potential attacks, leading to unauthorized access, data breaches, and disruption of services.