All incidents

Broadcom patches multiple critical VMware vCenter and ESXi vulnerabilities

vulnerabilityopenJul 29, 2026 — Aug 12, 2026
Broadcom patches multiple critical VMware vulnerabilities

BROADCOM has issued patches for a set of critical vulnerabilities affecting VMware vCenter Server, ESXi, Workstation and Fusion, with two flaws rated CVSS 9.8 that allow authentication bypass and remote code execution without prior credentials.

The most severe issues are CVE-2026-59309, an authentication bypass in the vCenter management plane, and CVE-2026-59310, a directory traversal vulnerability that can lead to arbitrary code execution; both require only network access to the vCenter service. A third high‑impact flaw, CVE-2026-47876, is an out‑of‑bounds write in ESXi that lets an attacker with administrative privileges inside a virtual machine execute code on the host system. These details are outlined in Broadcom’s security advisory published on 29 July 2026.

Additional vulnerabilities addressed include CVE-2026-41703, which can cause a denial of service, and CVE-2026-41709, a low‑severity issue that permits limited unauthenticated actions. The affected products span VMware ESXi versions, vCenter Server releases, Workstation and Fusion releases, with patched builds such as 9.1.0.0300, 9.0.2.0100 and 8.0 U3k indicated in the advisory. Patches are cumulative and no workarounds exist for the critical issues.

While there is currently no public proof‑of‑concept or evidence of active exploitation, researchers warn that the absence of observed attacks does not reduce the risk; once exploit code appears, unpatched systems could be compromised rapidly. Security firms such as Rapid7 have released detection checks to help organisations assess exposure, as noted in their analysis here.

Defenders should immediately apply the updates from Broadcom’s advisory, prioritising vCenter Server and ESXi hosts that are reachable from untrusted network segments. After patching, administrators should verify the version numbers and review logs for any signs of attempted authentication bypass or unusual process execution within virtual machines.

In addition to patching, it is advisable to limit administrative access to vCenter, enforce network segmentation, and employ intrusion detection rules that flag directory traversal attempts or out‑of‑bounds write patterns. Regular vulnerability scanning and timely re‑application of patches will help maintain a resilient posture against future threats targeting VMware infrastructure.

Intelligence briefing updated Jul 30, 2026

CVE-2026-59309 9.8 CVE-2026-59310 9.8 CVE-2026-41703 CVE-2026-41709 CVE-2026-47876
Root sourcesupport.broadcom.com
Timeline Coverage

Swipe to explore timeline