Three critical vulnerabilities — CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876 — are included in Broadcom's emergency security updates for VMware vCenter, ESX, Workstation, and Fusion, and administrators are being told to treat affected systems as immediately vulnerable.
Products covered and who is affected
Broadcom's advisory patches five vulnerabilities across VMware vCenter, ESX, Workstation, and Fusion. The flaws also affect products that contain vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Broadcom warns that organizations running versions released before the patched builds should assume they are vulnerable and take immediate action.
The three critical flaws and what they allow
- CVE-2026-59309 — A critical authentication bypass in the VMware Directory Service. Broadcom says an unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access.
- CVE-2026-59310 — A critical directory traversal vulnerability in the vCenter Syslog server. Broadcom reports an unauthenticated attacker with network access could use it to execute arbitrary code.
- CVE-2026-47876 — A critical out‑of‑bounds write in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a VM using VMXNET3 can exploit the flaw to execute code on the ESX host, producing a virtual machine escape. Virtual machines using other virtual network adapters are not affected by this specific bug.
The two vCenter flaws carry CVSS scores of 9.8; the VMXNET3 escape is rated 9.3. Two additional issues — CVE-2026-41703 (an out‑of‑bounds read) and CVE-2026-41709 (insufficient logging) — are lower-severity: CVE-2026-41703 is rated Important at 7.6 on ESX and Low at 2.7 on Workstation and Fusion, while CVE-2026-41709 is rated Low at 2.7.
Patch specifics, disruption, and compatibility caveats
Broadcom lists the vCenter fixes in vCenter builds 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k. ESX fixes appear in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k. Workstation and Fusion users running 25H2 must upgrade to 26H1 to address CVE-2026-41703. VMware Cloud Foundation 5.x and the affected telco products have separate patching instructions in the advisory.
There are no workarounds. Broadcom explicitly discourages switching virtual machines away from the VMXNET3 adapter as a mitigation because other adapters have contained security flaws and may reduce performance.
Patching will have operational effects. Broadcom says updating vCenter temporarily interrupts access to the vSphere Client and other management interfaces, though running virtual machines and containers will continue operating. ESX updates require a server restart; Broadcom recommends using vMotion to move VMs to other hosts and performing a rolling reboot of clusters. Virtual machines that cannot be migrated must be powered down for the restart. Supported environments can use ESX Live Patch to reduce disruption, but the vCenter updates are not eligible for Quick Patch.
Administrators should also note a compatibility restriction: the advisory explains a "back in time" restriction can occur when a patch updates a product branch to a newer build number than the target of a planned upgrade. Specifically, the vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x by reporting a "back in time" error; Broadcom says upgrade compatibility will be restored in later releases.
Why these fixes matter: attackers already target VMware infrastructure
Broadcom reports no indication that these specific vulnerabilities are being exploited in the wild. Still, the company notes VMware servers are commonly targeted because accessing vCenter or ESXi can expose large portions of an organization's servers and stored data. Ransomware gangs have created dedicated encryptors that specifically target VMware virtual machines. In December 2025, CISA warned that Chinese threat actors were compromising VMware vSphere servers to deploy BrickStorm malware, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft. CrowdStrike has observed attackers using the ESXi shell to create unregistered "ghost" virtual machines — a persistence technique it tracks as VirtualGHOST.
Those operational realities — high impact of host compromise and prior use of VMware-directed techniques by threat actors — are the context Broadcom cites in treating the updates as emergency fixes.
What this means for VM administrators, security teams, and procurement leaders
- VM administrators: Treat affected vCenter and ESX builds as vulnerable until updated; expect temporary management interruptions when applying vCenter patches and plan for ESXi host restarts (vMotion or powering down VMs as required).
- Security teams and incident responders: Note Broadcom reports no observed exploitation but should consider the advisory urgent; the history of targeted attacks (BrickStorm, VirtualGHOST, VM-focused ransomware) increases the operational risk profile.
- Procurement and platform owners: Be aware of the "back in time" compatibility restriction that can block upgrades to VMware Cloud Foundation 9.x after applying the vSphere 8.0/9.0 updates, and track Broadcom's promised later releases to restore upgrade paths.
Broadcom frames these fixes as an emergency change: "These issues qualify under ITIL methodologies as an emergency change, requiring prompt action from your organization," the company wrote in a supplemental FAQ. The vendor also warns of possible service impact during updates. Whether to patch immediately or stage changes through rolling maintenance windows is now a decision every affected organization must make against clear technical risk and operational cost.




