Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    July 30, 2026

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    July 30, 2026

    The OSINT Newsletter – Issue #116

    July 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»VMware fixes three critical flaws allowing auth bypass, VM escapes
    News

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    adminBy adminJuly 30, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    VMware

    Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

    The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

    Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.

    image

    The five vulnerabilities are summarized below:

    • CVE-2026-59309: A critical authentication bypass vulnerability in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system.
    • CVE-2026-59310: A critical directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker with network access to execute arbitrary code.
    • CVE-2026-47876: A critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape. Virtual machines using other virtual network adapters are not affected.
    • CVE-2026-41703: An out-of-bounds read vulnerability in ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges could exploit it to disclose information or cause a denial-of-service condition in the host process. On Workstation and Fusion, the impact is limited to information disclosure.
    • CVE-2026-41709: An insufficient logging vulnerability that allows a malicious ESX administrator to perform certain operations without them being logged.

    The three critical vulnerabilities are the two vCenter flaws, CVE-2026-59309 and CVE-2026-59310, which have CVSS scores of 9.8, and the VMXNET3 escape flaw, CVE-2026-47876, which is rated 9.3.

    The remaining issues are less severe, with CVE-2026-41703 rated as Important with a score of 7.6 on ESX. On Workstation and Fusion, its impact is limited to information disclosure, and it is rated Low with a score of 2.7.  CVE-2026-41709 is also rated Low at 2.7.

    The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.

    VMware Workstation and Fusion users running version 25H2 must upgrade to 26H1 to address CVE-2026-41703. VMware Cloud Foundation 5.x and the affected telco products have separate patching instructions in Broadcom’s advisory.

    There are no workarounds for the vulnerabilities, and Broadcom says switching virtual machines away from the VMXNET3 adapter is not advisable because other virtual network adapters have also contained security flaws and may reduce performance.

    Broadcom is treating these as emergency fixes, prompting admins to install them as soon as possible.

    “These issues qualify under ITIL methodologies as an emergency change, requiring prompt action from your organization,” Broadcom warned in a supplemental FAQ.

    However, there may be some impact to services as they are being updated.

    Broadcom says patching vCenter temporarily interrupts access to the vSphere Client and other management interfaces, but running virtual machines and containers will continue operating.

    VMware ESX updates require a server to be restarted, so Broadcom recommends admins use vMotion to move virtual machines to other hosts while clusters are updated through a rolling reboot. Virtual machines that cannot be migrated must be powered down during the restart.

    Supported environments can also use ESX Live Patch to reduce disruption, although the vCenter updates are not eligible for Quick Patch.

    Broadcom also warns that there may be a compatibility issue when upgrading VMware Cloud Foundation with the new patches.

    “Yes. A “back in time” restriction occurs when a patch updates a product branch that carries a newer build number than the target of a planned upgrade,” explains the FAQ.

    “The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a “back in time” error.”

    The company says upgrade compatibility will be restored in later releases.

    Broadcom says there is no indication that the vulnerabilities in this advisory are being exploited in the wild.

    However, VMware servers are commonly targeted in attacks because compromising VMware vCenter or ESXi servers can provide access to large portions of an organization’s servers and the data stored on them.

    For quite some time, many ransomware gangs have been creating dedicated encryptors that specifically target VMware virtual machines, as they have become common in the enterprise.

    In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to deploy BrickStorm malware, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft.

    CrowdStrike has also observed attackers using the ESXi shell to create unregistered “ghost” virtual machines that do not appear in the ESXi or vCenter web consoles, a persistence technique the company tracks as VirtualGHOST.

    While Broadcom has not observed exploitation of the newly patched vulnerabilities, administrators should apply the updates as soon as possible.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAmazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
    admin
    • Website

    Related Posts

    News

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    July 30, 2026
    News

    The OSINT Newsletter – Issue #116

    July 30, 2026
    News

    Mitigation Guidance for Supply Chain Compromise

    July 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    July 30, 2026

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    July 30, 2026

    The OSINT Newsletter – Issue #116

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.