logo

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

ID: 7b429773-e7f1-58f6-a4f6-a76388810f16

STIX ID: report--7b429773-e7f1-58f6-a4f6-a76388810f16

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-07-29

Date Updated: 2026-07-30

Author: Pierluigi Paganini

...
...

Broadcom released patches addressing five vulnerabilities in VMware ESXi, vCenter, Workstation, and Fusion, including critical flaws: a VMXNET3 VM escape (CVE-2026-47876, CVSS 9.3) that can allow an attacker with admin privileges inside a VM to execute code on the ESXi host, and two critical vCenter issues (CVE-2026-59309 and CVE-2026-59310, CVSS 9.8) enabling authentication bypass and remote code execution; additional high-severity flaws affecting information disclosure, DoS, and actions without login were also fixed, and Broadcom urges customers to apply updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.