
BROADCOM has released security patches for five vulnerabilities in VMware ESXi, vCenter, Workstation and Fusion that could let attackers bypass authentication and escape virtual machines to execute code on the underlying host according to its advisory. The flaws affect recent releases of the hypervisor and management platforms used in many enterprise environments.
The most severe flaw, tracked as CVE-2026-47876, is an out-of-bounds write in ESXi that allows a malicious actor with administrative privileges inside a virtual machine to run arbitrary code on the host, earning a CVSS score of 9.3 as detailed in the security advisory. Two additional issues, CVE-2026-59309 and CVE-2026-59310, affect vCenter Server; the first is an authentication bypass rated at CVSS 9.8 and the second is a directory traversal vulnerability that also scores 9.8 for arbitrary code execution as noted in the vulnerability breakdown.
Broadcom also addressed CVE-2026-41703, which can lead to a denial of service condition, and CVE-2026-41709, a low‑severity flaw that permits unauthorized actions without login. Both vulnerabilities affect the same product lines and are included in the cumulative updates released alongside the more critical flaws per the Broadcom notice.
The advisory notes that there are no known instances of active exploitation and no threat actors have been linked to these bugs. Despite the lack of observed attacks, Broadcom rates the vulnerabilities critical because of their potential impact on confidentiality, integrity and availability as stated in the advisory.
Administrators should apply the updates immediately, moving to ESXi, vCenter, Workstation or Fusion versions 9.1.0.0300, 9.0.2.0100 or 8.0 U3k as specified in the Broadcom notice according to the version guidance. The updates are available for download from the Broadcom support portal and must be applied to all affected systems to close the exposure.
Because the patches are cumulative, installing the latest release resolves all five issues and no workaround exists. Organisations are encouraged to monitor Broadcom’s security advisories for any further guidance and to verify successful patch deployment through their usual change‑management processes.