BROADCOM has released critical patches for five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion. The most severe, CVE-2026-47876, allows attackers with admin privileges in a VM to execute code on the ESXi host, rated with a CVSS score of 9.3. Other critical vulnerabilities include CVE-2026-59309, an authentication bypass in vCenter (9.8 CVSS), and CVE-2026-59310, allowing arbitrary code execution via a directory traversal vulnerability in vCenter (9.8 CVSS).
Broadcom also addressed CVE-2026-41703 and CVE-2026-41709, both with lower severities but still significant. Users are urged to apply the updates promptly.