logo

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

ID: e8a8ab01-665c-5068-a28b-72fddb14250e

STIX ID: report--e8a8ab01-665c-5068-a28b-72fddb14250e

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-29

Date Updated: 2026-08-07

Author: [email protected] (The Hacker News)

...
...

Broadcom released emergency security updates for VMware ESX, vCenter, Workstation, Fusion, and Cloud Foundation to address multiple vulnerabilities — including two critical CVSS 9.8 flaws (an authentication bypass and a directory-traversal RCE) and a VMXNET3 virtual machine escape — affecting a wide range of VMware versions. No evidence of active exploitation has been reported, but there are no workarounds and immediate patching is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.