Multiple Critical Vulnerabilities in VMware Products
5 August 2026
Attackers can exploit multiple vulnerabilities in VMware products to bypass authentication, execute arbitrary code, access sensitive information or cause denial-of-service. Patch immediately.
Background
Broadcom has released security updates addressing multiple critical vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876 and CVE-2026-41703) affecting VMware ESX, vCenter, Workstation and Fusion. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8, 9.8, 9.3 and 7.6 out of 10, respectively.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-59309: An authentication bypass vulnerability in the VMware Directory Service that allows an attacker with network access to vCenter to bypass authentication and gain unauthorised access to the system.
CVE-2026-59310: A directory traversal vulnerability in the vCenter Syslog server that allows an attacker with network access to execute arbitrary code.
CVE-2026-47876: An out-of-bounds write vulnerability in the VMXNET3 virtual network adapter that allows an attacker with local administrative privileges on a virtual machine using VMXNET3 to execute code on the underlying ESX host.
CVE-2026-41703: An out-of-bounds read vulnerability that allows an attacker with virtual machine deployment privileges to access sensitive information or cause a denial-of-service condition in the host process.
Affected Products
These vulnerabilities affect the following products:
CVE-2026-59309 & CVE-2026-59310
VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
VMware vCenter version 8.0
VMware Telco Cloud Platform (vCenter) versions 3.0, 4.x, 5.0.x, 5.1.x
VMware Telco Cloud Infrastructure (vCenter) version 3.0
CVE-2026-47876
VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
VMware ESX version 8.0
VMware Telco Cloud Platform versions (ESX) 5.0.x, 5.1.x
CVE-2026-41703
VMware Cloud Foundation (vCenter) versions 5.x, 9.0.x.x, 9.1.x.x
VMware vSphere Foundation (vCenter) versions 9.0.x.x, 9.1.x.x
VMware ESX version 8.0
VMware Telco Cloud Platform versions (ESX) 5.0.x, 5.1.x
VMware Workstation version 25H2
VMware Fusion version 25H2
Recommendations
Users and administrators of affected products are advised to update to the fixed versions immediately.
References
https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
https://cybersecuritynews.com/vmware-flaws-allow-authentication-bypass/
https://nvd.nist.gov/vuln/detail/CVE-2026-59309
https://nvd.nist.gov/vuln/detail/CVE-2026-59310
https://nvd.nist.gov/vuln/detail/CVE-2026-47876
