logo

Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System

ID: 73e9e3f6-c4df-50ee-ac25-e298a3527805

STIX ID: report--73e9e3f6-c4df-50ee-ac25-e298a3527805

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-29

Date Updated: 2026-07-29

Author: Guru Baran

...
...

Broadcom published VMSA-2026-0006 describing multiple critical VMware vulnerabilities—most notably CVE-2026-59309 (vCenter Directory Service authentication bypass) and CVE-2026-59310 (vCenter Syslog directory traversal → arbitrary code)—that can enable full management-plane compromise, alongside CVE-2026-47876 (VMXNET3 out-of-bounds write) enabling VM escape to ESX hosts and additional information-disclosure/insufficient-logging issues. The advisory covers vCenter, ESX, Workstation, Fusion, Cloud Foundation and Telco Cloud platforms and provides specific patched builds and upgrade paths; organizations should urgently prioritize applying the listed fixes for exposed vCenter and ESX instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.