www.securityweek.com 7/29/2026, 11:51:20 AM · external

Broadcom Warns of VMware Flaws Allowing Host Code Execution

Broadcom Warns of VMware Flaws Allowing Host Code Execution
Developing story vulnerability 2 articles tracked
Critical VMware vCenter authentication bypass flaw patched (CVE-2026-59309)

BROADCOM issued a security advisory regarding critical vulnerabilities in VMware products including ESXi, vCenter, Workstation, and Fusion. Notably, CVE-2026-47876 is a 'critical' out-of-bounds write vulnerability that allows code execution on the host by an attacker with local admin privileges. Another critical flaw, CVE-2026-59309, is an authentication bypass in vCenter. The last critical vulnerability, CVE-2026-59310, lets attackers execute code with network access.

A high-severity vulnerability (CVE-2026-41703) can lead to a denial of service, while a low-severity issue (CVE-2026-41709) allows unauthorized activities without login. Organizations are urged to apply patches promptly despite no known active exploitation.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline