At a glance:
-
Broadcom has released security updates for vulnerabilities affecting VMware environments that use vCenter, the management component included in VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud products, and standalone VMware vCenter Server deployments. Successful exploitation could provide unauthorized access to virtualization management systems or allow code execution on affected management servers, potentially exposing infrastructure administration functions.
-
Organizations running affected VMware platforms are advised to identify vCenter deployments, verify version levels, and apply the vendor updates released on July 29, 2026.
-
The same advisory also addresses additional vulnerabilities affecting VMware ESXi, Workstation, and Fusion, including a flaw that could allow a threat actor with administrative control of a virtual machine to execute code on the underlying ESXi host.
Threat summary
On July 29, 2026, Broadcom released security updates addressing five vulnerabilities affecting VMware vCenter, VMware ESXi, VMware Workstation, and VMware Fusion. The most critical issues are CVE-2026-59309 and CVE-2026-59310, two VMware vCenter vulnerabilities with CVSS v3 scores of 9.8.
- CVE-2026-59309 is an authentication bypass vulnerability in the VMware Directory Service. A threat actor with network access to a vulnerable vCenter server can bypass authentication and gain unauthorized access to the system.
- CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog Server that can allow a threat actor with network access to a vulnerable vCenter system to execute arbitrary code on the affected server.
VMware vCenter is the centralized management platform used to administer VMware virtual infrastructure. Organizations use vCenter to manage ESXi hosts, virtual machines, storage, networking, permissions, and automated operations across data centers and private cloud environments. Because vCenter manages core infrastructure components, unauthorized access to the platform can expose administrative functions across the virtualized environment.
Affected vCenter versions are included in VMware Cloud Foundation 9.0.x and 9.1.x, VMware vSphere Foundation 9.0.x and 9.1.x, VMware Cloud Foundation 5.x, VMware Telco Cloud Platform versions 3.0, 4.x, 5.0.x, and 5.1.x, VMware Telco Cloud Infrastructure 3.0, and standalone VMware vCenter Server 8.0 deployments.
The advisory also addresses CVE-2026-47876, an ESXi vulnerability in the VMXNET3 virtual network adapter with a CVSS v3 score of 9.3. Broadcom describes the issue as a virtual machine (VM) escape vulnerability and states that a threat actor with local administrative privileges on a virtual machine using a VMXNET3 adapter may exploit the vulnerability to execute code on the underlying ESXi host. Non-VMXNET3 virtual network adapters are not affected.
In addition, Broadcom released fixes for CVE-2026-41703, an information disclosure and denial-of-service vulnerability affecting ESXi, Workstation, and Fusion, and CVE-2026-41709, an ESXi vulnerability that allows certain administrative activities to occur without corresponding login records.
Analysis
VMware management platforms have been a recurring target for threat actors because they provide centralized administration of virtual infrastructure. Previous vCenter vulnerabilities, including CVE-2021-21972, CVE-2021-22005, and CVE-2023-34048, attracted significant attention from threat actors following disclosure. Public reporting and incident investigations have linked exploitation of vCenter vulnerabilities to unauthorized access, web shell deployment, ransomware activity, and compromise of virtualized environments.
CVE-2026-59309 and CVE-2026-59310 require network access to a vulnerable vCenter system. A threat actor may be able to reach vCenter after compromising a workstation, server, virtual machine, VPN account, or another system with access to the management network.
Organizations using vCenter to manage production workloads, ESXi hosts, storage, networking, and administrative operations are advised to identify vulnerable vCenter deployments and update them to fixed versions released by Broadcom. Remediation for CVE-2026-59309 and CVE-2026-59310 is available in VMware Cloud Foundation and VMware vSphere Foundation 9.1.0.0300, VMware Cloud Foundation and VMware vSphere Foundation 9.0.2.0100, and VMware vCenter Server 8.0 U3k. VMware Cloud Foundation 5.x environments are remediated through Broadcom's asynchronous patching process, while VMware Telco Cloud Platform and VMware Telco Cloud Infrastructure deployments are covered by product-specific update guidance. Broadcom reports no workarounds for either vulnerability.
CVE-2026-47876 is remediated through the updates released as part of VMSA-2026-0006. Unlike the vCenter vulnerabilities, exploitation requires local administrative privileges within a guest virtual machine that uses the VMXNET3 virtual network adapter. Organizations are advised to identify systems using VMXNET3 adapters and review administrative access within guest virtual machines while deploying updates. Broadcom reports no workaround for this vulnerability.