Recent security updates from Broadcom address several critical vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Among these, three vulnerabilities have been classified as critical due to their potential impact on system security.
Authentication Bypass and Code Execution Flaws
The most severe vulnerability, identified as CVE-2026-59309 with a CVSS score of 9.8, involves an authentication bypass in VMware vCenter. This flaw enables attackers with network access to circumvent authentication measures, granting them unauthorized system access.
A second critical flaw, CVE-2026-59310, also scored at 9.8, is a directory traversal vulnerability within vCenter. It allows attackers to execute arbitrary code remotely. These vulnerabilities have been mitigated in recent updates across several VMware products, such as VMware Cloud Foundation and vSphere Foundation.
Additional Vulnerabilities and Fixes
Broadcom has also patched other significant vulnerabilities. CVE-2026-47876, with a CVSS score of 9.3, is an out-of-bounds write issue in the VMXNET3 virtual network adapter of VMware ESX. This flaw allows code execution on the host if exploited by an attacker with local administrator privileges on a virtual machine.
Another vulnerability, CVE-2026-41703, involves an out-of-bounds read problem in VMware ESX, potentially leading to information disclosure or denial-of-service conditions. This issue has been addressed in updates for various VMware products, including Workstation and Fusion.
Security Enhancements and Future Outlook
Additionally, CVE-2026-41709, an insufficient logging vulnerability in VMware ESX, has been rectified. This flaw allowed malicious administrators to perform certain operations without logging. Broadcom assures users that no evidence suggests these vulnerabilities have been exploited in real-world scenarios.
While Broadcom has swiftly released patches to combat these threats, the company emphasizes the importance of updating systems promptly to maintain security integrity. Staying current with software updates is crucial to protect against potential exploitation and ensure robust defense mechanisms are in place.
