Broadcom patches critical VMware ESXi and vCenter vulnerabilities
This digest was compiled by AI from multiple sources — links to the originals are below.

Broadcom on Wednesday released patches for a critical VM escape vulnerability in VMware ESXi, tracked as CVE-2026-47876, that could allow attackers to execute arbitrary code on host systems. The advisory also addressed two critical vCenter Server flaws — an authentication bypass, CVE-2026-59309, and remote code execution, CVE-2026-59310. The company said it has not observed any in-the-wild exploitation but urged immediate updates.
Critical VM Escape Flaw
The most severe vulnerability, CVE-2026-47876, is an out-of-bounds write in ESXi’s VMXNET3 virtual network adapter. An attacker with local administrator privileges on a virtual machine using this adapter can exploit the flaw to escape the VM and execute arbitrary code on the underlying host system. VMware assigned a CVSS base score of 9.3, reflecting the high impact and low attack complexity. The VMXNET3 adapter is a paravirtualized network driver commonly deployed in enterprise environments, amplifying the risk.
vCenter Server Vulnerabilities
The advisory also fixes two critical flaws in vCenter Server. CVE-2026-59309 is an authentication bypass that can be exploited to gain unauthorized access to the management interface. CVE-2026-59310 allows an attacker with network access to execute arbitrary code on vCenter systems. Both vulnerabilities carry critical severity ratings, though specific CVSS scores were not disclosed in the initial advisory. vCenter is a central management platform, making these flaws especially dangerous for environments with exposed administrative consoles.
Additional Flaws and Patching Guidance
The update resolves two other vulnerabilities: a high-severity information disclosure and denial-of-service issue (CVE-2026-41703) affecting ESXi, Workstation, and Fusion, and a low-severity flaw (CVE-2026-41709) in ESXi that allows admin activity without logging. Broadcom stated it is not aware of any exploitation of these flaws in the wild. The company published an FAQ detailing patching requirements and impact assessments. Organizations are advised to apply the updates immediately, as VMware products are frequent targets of advanced persistent threat actors.
What's Next
Security teams are urged to prioritize patching internet-facing vCenter and high-value ESXi hosts, particularly those running VMXNET3 adapters. However, it remains unclear whether any threat actors developed exploits before the disclosure, given the history of zero-day attacks against VMware infrastructure.
2 sources
Broadcom patches critical VMware ESXi and vCenter vulnerabilities



