Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: hypervisor (1 article)Clear

Broadcom patches critical VMware flaws enabling VM escape and vCenter takeover

Broadcom released emergency patches for five VMware flaws, three of them critical, affecting ESXi, vCenter, Workstation, and Fusion. The most notable, CVE-2026-47876, is an out-of-bounds write in the ESXi VMXNET3 network adapter that lets an attacker with admin rights inside a guest virtual machine run code on the host, a VM escape. Two critical vCenter flaws follow: CVE-2026-59309 is an authentication bypass reachable over the network, and CVE-2026-59310, scored 9.8, allows code execution through a directory traversal. Broadcom warns the vCenter bypass could be chained with the escape or the code-execution flaw to seize the hypervisor without any guest foothold. No exploitation is reported yet.

Check
Apply the VMware fixes as an emergency change, since there are no workarounds, prioritizing vCenter and any ESXi hosts running virtual machines that use the VMXNET3 adapter.
Affected
Organizations running affected VMware ESXi, vCenter, Workstation, or Fusion (CVE-2026-47876, CVE-2026-59309, CVE-2026-59310); attackers can escape a VM to the host or bypass vCenter to compromise the hypervisor.
Fix
Upgrade to the fixed vCenter and ESXi builds Broadcom lists, restrict vCenter network access, and treat this as urgent, since attackers frequently target VMware after patches reveal the flaws.