securityaffairs.com 7/29/2026, 2:07:48 PM · external

Broadcom patches critical VMware flaws, including admin VM escape

Broadcom patches critical VMware flaws, including admin VM escape
Developing story vulnerability 4 articles tracked
VMware bugs allow authentication bypass and VM escape

BROADCOM has released critical patches for five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion. The most severe, CVE-2026-47876, allows attackers with admin privileges in a VM to execute code on the ESXi host, rated with a CVSS score of 9.3. Other critical vulnerabilities include CVE-2026-59309, an authentication bypass in vCenter (9.8 CVSS), and CVE-2026-59310, allowing arbitrary code execution via a directory traversal vulnerability in vCenter (9.8 CVSS).

Broadcom also addressed CVE-2026-41703 and CVE-2026-41709, both with lower severities but still significant. Users are urged to apply the updates promptly.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline