CVE Tools
Back to feed
Patch released ESXi cloud vCenter Broadcom auth-bypass

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Broadcom has issued security updates addressing several critical vulnerabilities in VMware products including vCenter, ESX, Workstation, and Fusion. Among them are two high-severity flaws—CVE-2026-59309 (authentication bypass) and CVE-2026-59310 (directory traversal)—that could allow remote attackers to gain unauthorized access or execute arbitrary code. Another notable flaw, CVE-2026-47876, enables local users to break out of a virtual machine and run code on the host system. Broadcom reports no evidence of real-world exploitation but urges administrators to apply patches immediately.