securityaffairs.com 29 Jul 2026, 13:02 UTC

Broadcom patches critical VMware flaws, including admin VM escape

Broadcom patches critical VMware flaws, including admin VM escape

BROADCOM has released critical patches for five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion. The most severe, CVE-2026-47876, allows attackers with admin privileges in a VM to execute code on the ESXi host, rated with a CVSS score of 9.3. Other critical vulnerabilities include CVE-2026-59309, an authentication bypass in vCenter (9.8 CVSS), and CVE-2026-59310, allowing arbitrary code execution via a directory traversal vulnerability in vCenter (9.8 CVSS).

Broadcom also addressed CVE-2026-41703 and CVE-2026-41709, both with lower severities but still significant. Users are urged to apply the updates promptly.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline