🔴 Critical  |  Source: The Hacker News


Broadcom has patched three critical vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion, the most severe of which (CVE-2026-59309, CVSS 9.8) allows an unauthenticated attacker with network access to vCenter to bypass authentication entirely. The other critical flaws enable remote code execution and VM escape, meaning an attacker could break out of a guest virtual machine to compromise the underlying host. Together, these vulnerabilities represent a significant risk to virtualised infrastructure, particularly in environments where vCenter is network-accessible.

Security Architect’s Take: Apply Broadcom’s security patches immediately, prioritising vCenter instances — patch CVE-2026-59309 first given its CVSS 9.8 score and unauthenticated attack vector. As an interim control, ensure vCenter management interfaces are isolated behind a dedicated management network or VPN and not directly reachable from production or internet-facing segments.

Original advisory: Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape