BROADCOM has released patches for critical vulnerabilities in VMware products, notably an authentication bypass in vCenter Server (CVE-2026-59309) which has a CVSS score of 9.8, allowing attackers unauthorized access. Other related vulnerabilities include directory traversal flaws and out-of-bounds write errors. The affected VMware products include ESX, vCenter, Workstation, and Fusion. Immediate updates are required, specifically to versions 9.1.0.0300, 9.0.2.0100, or 8.0 U3k.
The advisory emphasizes that patches are cumulative and that no workarounds exist for these critical issues. System administrators should prioritize these updates to safeguard their environments.