Broadcom fixes critical flaws in VMware vCenter and ESX

Broadcom closes critical VMware security gaps
Broadcom has released security updates for VMware ESX, vCenter, Workstation and Fusion, led by three critical vulnerabilities. CVE-2026-59309 and CVE-2026-59310 both have CVSS scores of 9.8; CVE-2026-47876 scores 9.3 and is characterized as a virtual machine escape.
CVE-2026-59309 is an authentication bypass. A malicious actor with network access to vCenter may bypass authentication and gain unauthorized access. CVE-2026-59310 is a directory-traversal issue that allows an attacker with the same level of network access to execute arbitrary code.
How a guest can expose the host
CVE-2026-47876 is an out-of-bounds write in the VMXNET3 virtual network adapter. Exploitation requires local administrative privileges inside a virtual machine using VMXNET3. From that position, an attacker may execute code on the underlying ESX host.
Broadcom also addressed CVE-2026-41703, rated 7.6, an out-of-bounds read that users with VM deployment privileges can trigger. It may cause information disclosure or denial of service; on VMware Workstation and Fusion, the impact is limited to information disclosure.
CVE-2026-41709, rated 2.7, concerns insufficient logging. It can allow a malicious administrator to perform certain operations without those actions being recorded.
Versions containing the fixes
The two vCenter fixes are included in VMware Cloud Foundation and VMware vSphere Foundation 9.1.0.0300 and 9.0.2.0100, as well as VMware vCenter 8.0 U3k. VMware Cloud Foundation 5.x receives an asynchronous patch to 8.0 U3k.
The VMXNET3 correction is available in ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025 and ESXi80U3k-25595708. Broadcom says it has found no evidence that any of the five vulnerabilities has been exploited in the wild.
Business implication
Teams should inventory network-accessible vCenter systems and map vCenter and ESX installations to the fixed releases. VM owners should also identify guests using VMXNET3 where local administrative access exists and confirm that relevant operations are logged after updating.

