Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
ID: 7b429773-e7f1-58f6-a4f6-a76388810f16
STIX ID: report--7b429773-e7f1-58f6-a4f6-a76388810f16
Feed Name: Security Affairs
Broadcom released patches addressing five vulnerabilities in VMware ESXi, vCenter, Workstation, and Fusion, including critical flaws: a VMXNET3 VM escape (CVE-2026-47876, CVSS 9.3) that can allow an attacker with admin privileges inside a VM to execute code on the ESXi host, and two critical vCenter issues (CVE-2026-59309 and CVE-2026-59310, CVSS 9.8) enabling authentication bypass and remote code execution; additional high-severity flaws affecting information disclosure, DoS, and actions without login were also fixed, and Broadcom urges customers to apply updates promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
