Broadcom Drops Critical VMware Patches: vCenter Auth Bypass and ESXi VM Escape on the Line
If you’re running VMware infrastructure right now, stop what you’re doing and check your patch levels. Broadcom just pushed out a security advisory (VMSA-2026-0006) that should set off alarm bells for any sysadmin, security engineer, or CISO managing virtualized environments. Five vulnerabilities got patched, and three of them are sitting at the top of the severity scale with CVSS scores that should make anyone nervous.
The Big Three: What Actually Got Fixed
1. vCenter Authentication Bypass (CVE-2026-59309) — CVSS 9.8
This one is nasty. Buried inside the VMware Directory Service, there’s a flaw that lets an attacker with nothing more than network access to your vCenter instance waltz right past authentication entirely. No stolen credentials, no brute-forcing passwords, no social engineering — just raw access to the crown jewel of your virtualization stack.
Think about what vCenter controls: your entire VM fleet, storage policies, network configurations, snapshots, and more. An unauthenticated attacker getting their hands on that is essentially game over for your virtual infrastructure.
2. vCenter Directory Traversal → RCE (CVE-2026-59310) — CVSS 9.8
The second critical hit lands in vCenter’s Syslog server. It’s a directory traversal bug that, when exploited, opens the door to arbitrary code execution. Again, all the attacker needs is network reachability to the vCenter box.
Pair this with the auth bypass above and you’ve got a nightmare scenario: first they get in without credentials, then they can traverse directories and drop payloads. These two bugs alone are enough to justify an all-hands patching session.
3. ESXi VM Escape via VMXNET3 (CVE-2026-47876) — CVSS 9.3
This is the one that virtualization security folks lose sleep over. The VMXNET3 virtual network adapter — the high-performance NIC that most modern VMware VMs use by default — has an out-of-bounds write vulnerability. If an attacker already has local admin privileges inside a VM using VMXNET3, they can break out of the guest and execute code directly on the underlying ESXi host.
Broadcom explicitly labels this a VM escape. What’s particularly interesting here is that this bug was reported by Nguyen Hoang Thach from STARLabs SG through the Pwn2Own competition, which tells you this wasn’t just a theoretical find — it’s the kind of vulnerability that gets demonstrated live on stage at hacking contests.
The silver lining? If you’re using E1000e or another non-VMXNET3 adapter, this specific flaw doesn’t apply to you. But let’s be honest — most production VMs are running VMXNET3 for the performance benefits.
The Supporting Cast: Two More Bugs Worth Knowing
Beyond the critical trio, Broadcom also patched:
- CVE-2026-41703 (CVSS 7.6): An out-of-bounds read affecting ESXi, Workstation, and Fusion. On ESXi, someone with VM deployment privileges could trigger information disclosure or knock the host process into a denial-of-service state. On Workstation and Fusion, the damage is limited to info disclosure.
- CVE-2026-41709 (CVSS 2.7): An insufficient logging issue in ESXi that lets a rogue admin perform certain operations without leaving an audit trail. Low severity on paper, but in compliance-heavy environments, invisible admin actions are a serious problem.
What Needs Patching and Where to Find It
Broadcom has been clear: no workarounds exist for the critical vCenter flaws. Patching is your only option. Here’s the breakdown:
Table
| Product | Affected Versions | Fixed Version |
|---|---|---|
| VMware Cloud Foundation / vSphere Foundation | 9.1.x.x | 9.1.0.0300 |
| VMware Cloud Foundation / vSphere Foundation | 9.0.x.x | 9.0.2.0100 |
| VMware vCenter | 8.0 | 8.0 U3k |
| VMware Cloud Foundation | 5.x | Async patch to 8.0 U3k |
For ESXi, the VM escape and logging fixes are available in builds ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, and ESXi80U3k-25595708. If you’re still on older releases, the advisory covers Cloud Foundation 5.2.3/5.2.4 and Telco-specific updates as well.
Workstation and Fusion users should upgrade from 25H2 to 26H1 to address CVE-2026-41703.
Why This Advisory Hits Different
VMware isn’t just another piece of software in the enterprise stack — it’s the literal foundation that entire data centers are built on. When vulnerabilities allow authentication bypass and VM escapes, we’re not talking about a compromised endpoint or a leaked database. We’re talking about an attacker potentially owning the hypervisor layer, which means they can see, manipulate, or destroy every VM running on that host.
The good news: Broadcom says there’s no evidence these flaws have been exploited in the wild yet.
But here’s the reality — now that the patches and technical details are public, the clock is ticking. Threat actors have a long history of targeting VMware products, and critical CVSS 9.8 bugs don’t stay unexploited for long once the security community starts analyzing them.
Bottom Line
If your vCenter server faces any network — internal or external — treat this as a drop-everything-and-patch situation. The auth bypass and directory traversal flaws are about as severe as it gets for a virtualization management platform. ESXi hosts running VMXNET3 should be next on your list, especially if you operate multi-tenant environments where one compromised guest VM could put the entire host at risk.
Broadcom has published a supplemental FAQ alongside the advisory for anyone needing clarification on impact or patch sequencing. Don’t sleep on this one.
High demand. Switched to K2.6 Instant for speed. Upgrade to use K2.6 Thinking.