Tech News

VMware: 3 Critical Flaws in vCenter and ESX, Including a VM Escape

On July 29, 2026, Broadcom disclosed five vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. Three of them are critical, with CVSS scores ranging from 9.3 to 9.8 out of 10. What are the risks? How can you protect yourself? Here’s the essential information you need to know about these three critical flaws.

Two Critical Flaws in VMware vCenter

It had been a while since VMware ESX and vCenter had seen critical vulnerabilities. But now Broadcom has just patched some serious issues in its products. Let’s start with the two critical vulnerabilities found in VMware vCenter, which, as a reminder, is the control point for any vSphere infrastructure.

  • CVE-2026-59309 (CVSS 9.8 / 10): an authentication bypass in the VMware Directory Service. "A malicious actor with network access to vCenter may exploit this flaw to bypass authentication and gain unauthorized access to the system.", Broadcom states in its bulletin.
  • CVE-2026-59310 (CVSS 9.8 / 10): a directory traversal flaw in the vCenter Syslog server, exploitable by an attacker with network access to execute arbitrary code.

These are two vulnerabilities that can be exploited over the network without any specific privileges and without any third-party interaction. In this case, the attacker only needs to be able to communicate with the targeted vCenter server. This is a reminder that compromising vCenter makes it possible to take control of ESX hosts and virtual machines.

The relatively good news: Broadcom says it has no evidence suggesting these flaws are being exploited in the wild. As always, the situation can change: many flaws have already been listed in the CISA KEV catalog.

VMXNET3: a Virtual Machine Escape on ESX

The third critical flaw, identified as CVE-2026-47876 (CVSS 9.3 / 10), is an out-of-bounds write in the VMXNET3 virtual network adapter available on VMware ESX. According to Broadcom, exploiting this flaw can lead to a virtual machine escape: "An attacker who already has local administrative privileges inside a virtual machine using the VMXNET3 virtual network adapter can execute code on the ESX host." - In other words, it is possible to compromise the ESX host from the guest operating system of a virtual machine. As you probably guessed, only VMs equipped with a VMXNET3 network adapter are affected.

The scenario linked to this flaw is similar to the one from July 2025, when a flaw in the same VMXNET3 adapter already made it possible to pivot to the host, as well as the zero-day exploited in early 2025 to take control of other VMs from a compromised machine. It should be noted that this vulnerability was discovered by Nguyen Hoang Thach of STARLabs SG, as part of the Pwn2Own contest organized by the Zero Day Initiative.

In its security bulletin, Broadcom states: "Non-paravirtualized devices, such as the e1000 virtual network card, have also historically had driver vulnerabilities. Choosing those would also mean giving up the performance gains offered by paravirtualized drivers, which can improve I/O performance by up to 40%. Update ESX rather than changing the virtual hardware."

How Can You Protect Yourself?

To protect against these various security flaws, Broadcom has released a set of security patches. Here is the summary:

  • vCenter: 9.1.0.0300 for the 9.1.x branch, 9.0.2.0100 for the 9.0.x branch, 8.0 U3k for the 8.0 branch.
  • ESX: ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025 or ESXi80U3k-25595708 depending on the branch.
  • Workstation and Fusion: version 26H1, as the 25H2 branch is affected by CVE-2026-41703.

Find all the details in the security bulletin published by Broadcom.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.