HackMyIP
← Back to News
2026-07-29 The Hacker News

Critical VMware Flaws Enable Auth Bypass, Code Execution, and VM Escape

VulnerabilityCloud SecurityAuthentication

Broadcom has shipped urgent security updates to address five vulnerabilities affecting VMware ESX, vCenter Server, Workstation, and Fusion, three of which carry critical severity ratings and pose serious risks to enterprise virtualized environments. The most severe, CVE-2026-59309 (CVSS 9.8), is an authentication bypass in vCenter Server that allows a remote attacker with network access to gain unauthorized administrative control without valid credentials. Closely tied to it is CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in vCenter that enables arbitrary code execution by an unauthenticated network actor, effectively chaining with the auth bypass to deliver full system compromise.

The third critical issue, CVE-2026-47876 (CVSS 9.3), is an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter within VMware ESX. Broadcom explicitly classified this as a virtual machine escape: an attacker who already holds local administrative privileges inside a guest VM can leverage the flaw to execute code on the underlying ESXi host, breaking the isolation boundary that underpins multi-tenant virtualization. Administrators are urged to apply the patches immediately and verify host integrity, since undetected host-level compromise can grant attackers persistent access to every VM running on the affected hypervisor. Organizations should also audit network exposure of management interfaces using a reliable port scanner to ensure vCenter is not inadvertently reachable from untrusted networks.

Two additional flaws round out the advisory. CVE-2026-41703 (CVSS 7.6) is an out-of-bounds read in VMware ESX exploitable by users with VM deployment privileges, leading to information disclosure or denial-of-service, with reduced impact on Workstation and Fusion. CVE-2026-41709 (CVSS 2.7) is an insufficient logging flaw that lets a malicious administrator perform actions without leaving an audit trail, complicating enterprise security posture assessments and incident response. Patches are available in VMware Cloud Foundation and vSphere Foundation 9.1.0.0300 and 9.0.2.0100, vCenter 8.0 U3k, and corresponding ESXi 8.0 U3k builds, with fixes also shipping in Workstation 26H1 and Fusion 26H1. While Broadcom reports no evidence of active exploitation, defenders should treat these as priority deployments and verify the integrity of management-plane TLS configurations with a thorough SSL/TLS checker to rule out downgrade or interception risks during remediation.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →