Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System
ID: 73e9e3f6-c4df-50ee-ac25-e298a3527805
STIX ID: report--73e9e3f6-c4df-50ee-ac25-e298a3527805
Feed Name: cybersecurityNews.com
Broadcom published VMSA-2026-0006 describing multiple critical VMware vulnerabilities—most notably CVE-2026-59309 (vCenter Directory Service authentication bypass) and CVE-2026-59310 (vCenter Syslog directory traversal → arbitrary code)—that can enable full management-plane compromise, alongside CVE-2026-47876 (VMXNET3 out-of-bounds write) enabling VM escape to ESX hosts and additional information-disclosure/insufficient-logging issues. The advisory covers vCenter, ESX, Workstation, Fusion, Cloud Foundation and Telco Cloud platforms and provides specific patched builds and upgrade paths; organizations should urgently prioritize applying the listed fixes for exposed vCenter and ESX instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
