CVE Tools
Back to feed
Patch released vCenter auth-bypass ESX VMware privilege-escalation

VMware fixes three critical flaws allowing auth bypass, VM escapes

BleepingComputer·By Lawrence Abrams··4 min read
CVE Tools coverage

Broadcom has issued security updates addressing five vulnerabilities in VMware products, including three critical flaws that enable authentication bypass, remote code execution, and virtual machine escape. The most severe issues—CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876—affect vCenter and ESX systems, with CVSS scores up to 9.8. These flaws could allow unauthenticated attackers to gain unauthorized access or escalate privileges to the host system. Affected products include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms. Broadcom urges immediate patching, noting no workarounds are available and that delays could expose infrastructure to potential attacks.