mimile
Back to feed

Broadcom patches critical VMware ESXi and vCenter vulnerabilities

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Broadcom patches critical VMware ESXi and vCenter vulnerabilities

Broadcom on Wednesday released patches for a critical VM escape vulnerability in VMware ESXi, tracked as CVE-2026-47876, that could allow attackers to execute arbitrary code on host systems. The advisory also addressed two critical vCenter Server flaws — an authentication bypass, CVE-2026-59309, and remote code execution, CVE-2026-59310. The company said it has not observed any in-the-wild exploitation but urged immediate updates.

Critical VM Escape Flaw

The most severe vulnerability, CVE-2026-47876, is an out-of-bounds write in ESXi’s VMXNET3 virtual network adapter. An attacker with local administrator privileges on a virtual machine using this adapter can exploit the flaw to escape the VM and execute arbitrary code on the underlying host system. VMware assigned a CVSS base score of 9.3, reflecting the high impact and low attack complexity. The VMXNET3 adapter is a paravirtualized network driver commonly deployed in enterprise environments, amplifying the risk.

vCenter Server Vulnerabilities

The advisory also fixes two critical flaws in vCenter Server. CVE-2026-59309 is an authentication bypass that can be exploited to gain unauthorized access to the management interface. CVE-2026-59310 allows an attacker with network access to execute arbitrary code on vCenter systems. Both vulnerabilities carry critical severity ratings, though specific CVSS scores were not disclosed in the initial advisory. vCenter is a central management platform, making these flaws especially dangerous for environments with exposed administrative consoles.

Additional Flaws and Patching Guidance

The update resolves two other vulnerabilities: a high-severity information disclosure and denial-of-service issue (CVE-2026-41703) affecting ESXi, Workstation, and Fusion, and a low-severity flaw (CVE-2026-41709) in ESXi that allows admin activity without logging. Broadcom stated it is not aware of any exploitation of these flaws in the wild. The company published an FAQ detailing patching requirements and impact assessments. Organizations are advised to apply the updates immediately, as VMware products are frequent targets of advanced persistent threat actors.

What's Next

Security teams are urged to prioritize patching internet-facing vCenter and high-value ESXi hosts, particularly those running VMXNET3 adapters. However, it remains unclear whether any threat actors developed exploits before the disclosure, given the history of zero-day attacks against VMware infrastructure.

2 sources

Broadcom patches critical VMware ESXi and vCenter vulnerabilities