Security
VMware ESX, vCenter, Workstation, and Fusion: Updates close critical gaps
Image: Primary Broadcom released security updates on Wednesday to close critical vulnerabilities in VMware ESX, vCenter, Workstation and Fusion, the company said in a security advisory.
Attackers can exploit a flaw in VMware Directory Service to bypass authentication and gain unauthorized access without a login, identified as CVE-2026-59309 with a CVSS score of 9.8. A path traversal vulnerability in the Syslog server allows arbitrary code injection and execution, tracked as CVE-2026-59310 with a CVSS score of 9.8. A memory boundary issue in the VMXNET3 virtual network adapter lets local administrators break out from a virtual machine to the host system, listed as CVE-2026-47876 with a CVSS score of 9.3.
Additional high-severity flaws include an out-of-bounds read vulnerability allowing information leakage or denial of service, and a logging gap that permits certain administrative operations to go unrecorded. Broadcom linked updated software packages for affected products, including VMware Cloud Foundation, vSphere Foundation, vCenter, ESXi, Fusion and Workstation.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from heise and reviewed by the T&B editorial agent team.