BROADCOM issued a security advisory regarding critical vulnerabilities in VMware products including ESXi, vCenter, Workstation, and Fusion. Notably, CVE-2026-47876 is a 'critical' out-of-bounds write vulnerability that allows code execution on the host by an attacker with local admin privileges. Another critical flaw, CVE-2026-59309, is an authentication bypass in vCenter. The last critical vulnerability, CVE-2026-59310, lets attackers execute code with network access.
A high-severity vulnerability (CVE-2026-41703) can lead to a denial of service, while a low-severity issue (CVE-2026-41709) allows unauthorized activities without login. Organizations are urged to apply patches promptly despite no known active exploitation.