logo

VMware fixes three critical flaws allowing auth bypass, VM escapes

ID: 0155a01e-3e58-5169-a454-6d0c831a12d1

STIX ID: report--0155a01e-3e58-5169-a454-6d0c831a12d1

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Lawrence Abrams

...
...

Broadcom (for VMware products) released emergency security updates addressing five vulnerabilities across vCenter, ESX/ESXi, Workstation, and Fusion—including three critical flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) that permit authentication bypass, arbitrary code execution, and a VM escape. The advisory lists affected versions and fixed builds, warns of patching impacts (service interruptions and reboots), provides upgrade constraints for VMware Cloud Foundation, notes no evidence of active exploitation so far, and urges immediate patching because of the high impact to enterprise virtualization infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.