Friday, July 31, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Broadcom Ships Emergency Patches for Critical VMware Auth Bypass and VM Escape Bugs

Three critical vulnerabilities in VMware vCenter and ESXi, with CVSS scores up to 9.8, allow attackers to bypass authentication, execute code, or escape virtual machines. Broadcom urges immediate patching; no workarounds exist.

VMware brand mark representing the affected virtualization products. Brand icon via Simple Icons.
VMware brand mark representing the affected virtualization products. Brand icon via Simple Icons.

Broadcom has released emergency security updates to plug five vulnerabilities across VMware’s core virtualization products, including a trio of critical flaws that can let attackers sidestep authentication, run arbitrary code, or break out of a guest virtual machine onto the underlying host.

As reported by BleepingComputer, the patches address vCenter, ESXi, Workstation, Fusion, and several bundled platforms — VMware Cloud Foundation, vSphere Foundation, and Telco Cloud offerings. The two most severe bugs, CVE-2026-59309 and CVE-2026-59310, both carry a 9.8 CVSS score and reside in vCenter Server, where they enable complete authentication bypass. A third critical vulnerability, CVE-2026-47876, scored 9.3, affects the VMXNET3 virtual network adapter in ESXi and could be exploited by a malicious guest to escape to the host. Two other issues rank lower: CVE-2026-41703 (important, 7.6 on ESXi; low, 2.7 on Workstation and Fusion for information disclosure) and CVE-2026-41709 (low, 2.7).

Broadcom warns that any deployment running a version older than the patched releases should be treated as compromised. Fixes are available in vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k; ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k; and Workstation/Fusion 26H1 (replacing 25H2). Cloud Foundation 5.x and affected telco products have separate patching instructions detailed in Broadcom’s advisory.

No temporary mitigations exist. The company explicitly advises against swapping VMXNET3 adapters for other virtual NICs, citing historical security issues in those alternatives and potential performance regressions. The updates are classified as an emergency change under ITIL practices, prompting Broadcom to tell administrators they “require prompt action from your organization.”

Patching vCenter will briefly disrupt the vSphere Client and management interfaces, though running virtual machines and containers continue unharmed. ESXi fixes mandate a host reboot. To minimize downtime, admins can leverage vMotion to migrate workloads to other hosts during a rolling cluster update; VMs that cannot be migrated must be powered off. ESX Live Patch can further reduce reboot impact, but vCenter updates do not qualify for Quick Patch.

A compatibility caveat applies to VMware Cloud Foundation upgrades. Applying these patches may trigger a “back in time” restriction that blocks an upgrade to Cloud Foundation 9.x, displaying an error. Broadcom says compatibility will be restored in future releases.

While no exploitation of these specific flaws has been observed in the wild, VMware infrastructure remains a prime target for financially motivated and state-backed adversaries. The source material notes that ransomware groups have long built dedicated encryptors for VMware virtual machines given their ubiquity in enterprise datacenters. In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about Chinese threat actors compromising vSphere servers to plant the BrickStorm malware, spin up hidden rogue VMs, and steal cloned VM snapshots to harvest credentials. Separately, CrowdStrike has tracked a persistence technique dubbed VirtualGHOST wherein attackers abuse the ESXi shell to create unregistered “ghost” virtual machines invisible in the management consoles.

With no workarounds available and the critical severity of the flaws, Broadcom and BleepingComputer strongly recommend that administrators apply the updates immediately, prioritizing VMware systems given their concentrated role in managing large swaths of enterprise servers and data.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Spotify brand mark in green, used to represent the Running Mode feature. Brand icon via Simple Icons.
Software

Spotify’s New Running Mode Uses AI to Curate Workout Playlists

Xbox brand logo representing the console service outage. Brand icon via Simple Icons.
Gaming

Xbox Outage Prevents Disc-Based Play, Fueling Digital Ownership Fears

Google Play brand mark representing the Play Signal API. Brand icon via Simple Icons.
Software

Google to Roll Out Play Signal API Globally by End of 2026 for Age Assurance