VMware fixes three critical flaws allowing auth bypass, VM escapes
ID: 0155a01e-3e58-5169-a454-6d0c831a12d1
STIX ID: report--0155a01e-3e58-5169-a454-6d0c831a12d1
Feed Name: Bleeping Computer
Broadcom (for VMware products) released emergency security updates addressing five vulnerabilities across vCenter, ESX/ESXi, Workstation, and Fusion—including three critical flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) that permit authentication bypass, arbitrary code execution, and a VM escape. The advisory lists affected versions and fixed builds, warns of patching impacts (service interruptions and reboots), provides upgrade constraints for VMware Cloud Foundation, notes no evidence of active exploitation so far, and urges immediate patching because of the high impact to enterprise virtualization infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
