
BROADCOM has issued a security advisory warning of multiple vulnerabilities in VMware products that could allow an attacker to execute code on the underlying host, according to a report by SecurityWeek here. The flaws affect ESXi, vCenter Server, Workstation and Fusion, putting virtualised environments at risk of compromise. Patches have been released but organisations must apply them promptly to avoid potential exposure.
According to the advisory, Broadcom identifies five distinct tracking numbers. CVE-2026-47876 is an out-of-bounds write flaw that lets a locally authenticated administrator run arbitrary code on the host. CVE-2026-59309 is an authentication bypass in vCenter Server that can be exploited remotely without credentials. CVE-2026-59310 permits code execution on the host when an attacker has network access to the management interface. CVE-2026-41703 could trigger a denial of service condition, while CVE-2026-41709 permits unauthorised actions without requiring a login.
According to the accompanying notes, CVE-2026-59309 carries a CVSS score of 9.8, reflecting its potential impact. The out-of-bounds write in CVE-2026-47876 is rated as critical by the vendor, although a numeric score is not supplied. The remaining issues are classified as high or low severity, with CVE-2026-41703 marked as high and CVE-2026-41709 as low. Exploitation of the network based flaws requires the attacker to reach the relevant service, while the local admin privilege requirement limits the scope of the out-of-bounds write.
Broadcom states that there is no evidence of active exploitation in the wild and no specific threat actors have been linked to these vulnerabilities. Nevertheless, the presence of a remote authentication bypass and a network based code execution flaw raises the likelihood of opportunistic attacks once details become public. The advisory notes that the patches are cumulative and that no workarounds exist for the affected versions.
Administrators should prioritise updating to the patched releases: ESXi versions 9.1.0.0300, 9.0.2.0100 or 8.0 U3k, vCenter Server to the corresponding releases, and the latest versions of Workstation and Fusion. The updates are available through the Broadcom support portal and applying them promptly is the only reliable mitigation. Testing the patches in a staging environment before rollout can help avoid disruption.
In addition to applying updates, organisations should review access controls on management interfaces, restrict network reach to trusted segments and monitor logs for unusual authentication attempts or privilege changes. Keeping inventories of virtualisation assets up to date will assist in verifying that all instances have been patched.