Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape — Ravie LakshmananJul 29, 2026Vulnerability / Enterprise Security [https://blog
What’s new: Broadcom has released security updates for multiple VMware products, addressing three critical vulnerabilities: CVE-2026-59309 (authentication bypass in vCenter), CVE-2026-59310 (directory traversal allowing code execution), and CVE-2026-47876 (out-of-bounds write in VMXNET3 allowing code execution on the host). These vulnerabilities have CVSS scores of 9.8, 9.8, and 9.3, respectively.
Who’s affected
Impacted products include VMware ESX, vCenter, Workstation, and Fusion. Specific versions affected are VMware Cloud Foundation and VMware vSphere Foundation versions 9.1.x.x (fixed in 9.1.0.0300), 9.0.x.x (fixed in 9.0.2.0100), and VMware vCenter version 8.0 (fixed in 8.0 U3k).
What to do
- Update VMware Cloud Foundation and VMware vSphere Foundation to versions 9.1.0.0300 or 9.0.2.0100.
- Patch VMware vCenter to version 8.0 U3k.
- Apply fixes for CVE-2026-47876, CVE-2026-41703, and CVE-2026-41709 as specified in the advisory.



