Broadcom has released emergency security updates for five vulnerabilities affecting VMware vCenter, ESX and ESXi, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and several VMware Telco products.
The July 29 release, tracked as VMSA-2026-0006, includes two critical vCenter vulnerabilities that can be exploited remotely without authentication and a critical VM escape flaw that could allow code execution on an underlying ESXi host.
Broadcom says it has no information indicating that any of the vulnerabilities have been exploited in the wild. However, there are no available workarounds, and the company classifies the updates as an emergency change requiring prompt action.
Authentication Bypass Affects VMware vCenter
The first critical vulnerability, CVE-2026-59309, is an authentication bypass issue in VMware Directory Service with a CVSS score of 9.8.
An unauthenticated attacker with network access to vCenter could exploit the flaw to bypass authentication and gain unauthorized access to the management system.
Because vCenter provides centralized control over VMware environments, unauthorized access could expose administrative functions, infrastructure configurations, virtual machine inventories, credentials, and other sensitive management data.
The vulnerability is present regardless of whether the environment uses Enhanced Linked Mode, Integrated Windows Authentication, or Active Directory integration.
Syslog Flaw Can Lead to Remote Code Execution
CVE-2026-59310 is a second critical vCenter vulnerability with a CVSS score of 9.8.
The directory traversal flaw exists in the vCenter Syslog server and can allow a remote, unauthenticated attacker with network access to execute arbitrary code.
Broadcom’s supplemental security guidance confirms that both vCenter vulnerabilities can be exploited without first obtaining valid credentials.
Organizations should install the following fixed vCenter versions or a newer cumulative release:
VMware vCenter 9.1.0.0300
VMware vCenter 9.0.2.0100
VMware vCenter 8.0 Update 3k
Updating vCenter briefly interrupts access to the vSphere Client and other management interfaces, but Broadcom says running virtual machine and container workloads will continue operating during the update.
VMXNET3 Flaw Allows ESXi VM Escape
The most serious ESXi-specific vulnerability is CVE-2026-47876, an out-of-bounds write in the VMXNET3 virtual network adapter.
The flaw carries a CVSS score of 9.3 and can allow an attacker who already has local administrative privileges inside a virtual machine to execute code on the underlying ESXi host.
This crosses the security boundary separating a guest virtual machine from the hypervisor and is therefore classified as a VM escape.
Only virtual machines configured with a VMXNET3 virtual network adapter are affected. Virtual machines using other virtual adapters are not vulnerable to this specific issue.
Broadcom does not recommend switching affected systems to older, non-paravirtualized adapters such as e1000 as a long-term mitigation. Those devices have had their own security vulnerabilities and provide lower performance. Administrators should update ESXi instead.
The VMXNET3 flaw is located on the ESXi side of the communication channel, meaning VMware Tools does not need to be updated specifically to address CVE-2026-47876.
Fixed ESXi versions include:
ESXi 9.1.0.0200, build 25557999
ESXi 9.0.2.0100, build 25595025
ESXi 8.0 Update 3k, build 25595708
Updating ESXi normally requires restarting the host. Organizations with clustered environments can use vMotion to relocate workloads and perform rolling host reboots. Broadcom says Live Patch may also be available for supported versions and configurations.
Additional Information Disclosure and Logging Flaws
VMSA-2026-0006 also addresses CVE-2026-41703, an out-of-bounds read affecting ESX, Workstation, and Fusion.
An attacker with virtual machine deployment privileges could exploit the vulnerability to disclose information or, more likely, cause a denial-of-service condition in the ESXi host process. On VMware Workstation and Fusion, the impact is limited to information disclosure.
Workstation 25H2 and Fusion 25H2 users should update to Workstation or Fusion 26H1.
The final vulnerability, CVE-2026-41709, is a low-severity insufficient logging issue in ESX. A malicious administrator could perform certain operations without those actions being recorded, potentially reducing the visibility available during security monitoring or forensic investigations.
No Workarounds Available
Broadcom says there are no workarounds for the five vulnerabilities. Network segmentation, management-interface restrictions, and other defensive controls may reduce exposure, but they do not replace the security updates.
The advisory affects supported versions released before those listed as fixed. Broadcom also warns that organizations using unsupported VMware versions should assume they are vulnerable.
VMware vSphere 7 reached the end of general support on October 2, 2025. Broadcom says patches may be provided through the support portal at a later date, but organizations should not assume unsupported installations are safe simply because they are absent from the primary response matrix.
The company has not observed exploitation in the wild, but VMware infrastructure remains a high-value target because compromising a hypervisor or centralized management server can provide access to numerous workloads simultaneously.
Administrators should inventory affected vCenter and ESXi installations, restrict management interfaces to trusted networks, install the cumulative updates, and verify that all hosts report the expected patched build numbers.