Broadcom has released emergency security updates to address multiple vulnerabilities affecting VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion, including three critical flaws that could allow authentication bypass, remote code execution, and virtual machine escape. The company has urged customers to apply the updates immediately, noting that no workarounds are currently available for the disclosed issues. Although Broadcom stated that it has not found evidence indicating the vulnerabilities have been exploited in real world attacks, it has classified the updates as an emergency change because of the potential impact on affected systems. The security issues affect several VMware products used across enterprise environments, making timely patching important for organizations relying on VMware virtualization infrastructure.
The most severe vulnerability, tracked as CVE 2026 59309 with a CVSS score of 9.8, is an authentication bypass flaw affecting VMware vCenter. According to Broadcom, an attacker with network access to a vulnerable vCenter server could exploit the issue to bypass authentication and gain unauthorized access to the system. Another critical vulnerability, CVE 2026 59310, also assigned a CVSS score of 9.8, is a directory traversal flaw in VMware vCenter that could allow an attacker with network access to execute arbitrary code on affected systems. Broadcom has released fixes for VMware Cloud Foundation and VMware vSphere Foundation versions 9.1.x.x in version 9.1.0.0300, VMware Cloud Foundation and VMware vSphere Foundation versions 9.0.x.x in version 9.0.2.0100, VMware vCenter version 8.0 in update 8.0 U3k, and VMware Cloud Foundation 5.x through an asynchronous patch to version 8.0 U3k. Organizations running these affected versions are advised to deploy the available updates as soon as possible to reduce potential security risks.
In addition to the two critical vCenter vulnerabilities, Broadcom addressed three other security flaws across VMware products. CVE 2026 47876, with a CVSS score of 9.3, is an out of bounds write vulnerability in the VMXNET3 virtual network adapter used by VMware ESX. Broadcom described the issue as a virtual machine escape vulnerability because an attacker with local administrative privileges inside a virtual machine using the VMXNET3 adapter could execute code on the underlying ESX host. The flaw has been fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi 9.1.0.0200 25557999 and ESXi 9.0.2.0100 25595025, along with VMware ESX ESXi80U3k 25595708. Another vulnerability, CVE 2026 41703 with a CVSS score of 7.6, is an out of bounds read issue that could be triggered by an attacker with virtual machine deployment privileges. The flaw may result in information disclosure or denial of service on VMware ESX, while its impact on VMware Workstation and VMware Fusion is limited to information disclosure. Broadcom has issued fixes through updated releases of VMware ESX, VMware Workstation 26H1, VMware Fusion 26H1, VMware Cloud Foundation, and VMware vSphere Foundation.
Broadcom also resolved CVE 2026 41709, an insufficient logging vulnerability in VMware ESX with a CVSS score of 2.7. The issue could allow a malicious administrator to perform specific operations without those actions being recorded in system logs. Security updates for this flaw are available in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi 9.1.0.0 25370933 and ESXi 9.0.2.0100 25595025, as well as VMware ESX ESXi80U3j 25429389. While Broadcom confirmed that none of the disclosed vulnerabilities are known to have been exploited in active attacks, the company emphasized that customers should install the latest security updates without delay because no alternative mitigation measures are available. The updates are intended to strengthen the security of VMware environments by addressing vulnerabilities that could otherwise expose enterprise infrastructure to unauthorized access, code execution, information disclosure, or host level compromise.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





