CVE-2026-59309 (CVSS 9.8) is an authentication-bypass in VMware vCenter that "a malicious actor with network access to vCenter may exploit ... to bypass authentication and gain unauthorized access to the system," Broadcom said.
CVE-2026-59309 and CVE-2026-59310: vCenter authentication bypass and directory traversal
Broadcom released security updates this week to fix multiple vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. The vendor says three of those flaws have been designated critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), described as an authentication bypass in VMware vCenter; Broadcom warned that a malicious actor with network access to vCenter could exploit the issue to gain unauthorized access.
The second critical-rated issue is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in vCenter that Broadcom says a malicious actor with network access can exploit to execute arbitrary code. Broadcom lists fixes for these two vulnerabilities in multiple product branches:
- VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x — Fixed in 9.1.0.0300
- VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x — Fixed in 9.0.2.0100
- VMware vCenter version 8.0 — Fixed in 8.0 U3k
- VMware Cloud Foundation versions 5.x — Async patch to 8.0 U3k
CVE-2026-47876: VMXNET3 out-of-bounds write and virtual machine escape
Also addressed in Broadcom's advisory is CVE-2026-47876 (CVSS score: 9.3), an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter of VMware ESX. Broadcom characterized the issue as a virtual machine escape, saying: "An attacker who already holds local administrative privileges inside a virtual machine that uses the VMXNET3 virtual network adapter may execute code on the ESX host."
Broadcom lists the following fixes for CVE-2026-47876:
- VMware Cloud Foundation and VMware vSphere Foundation — ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025
- VMware ESX — ESXi80U3k-25595708
CVE-2026-41703 and CVE-2026-41709: information disclosure, DoS and logging gaps
Broadcom's advisory also addresses two additional vulnerabilities.
- CVE-2026-41703 (CVSS score: 7.6) — an out-of-bounds read in VMware ESX that a malicious actor with VM deployment privileges could trigger, potentially leading to information disclosure or a denial-of-service condition. On VMware Workstation and Fusion, Broadcom says the impact is limited to information disclosure. Fixes are listed across product lines, including ESXi builds and Workstation/Fusion releases.
- CVE-2026-41709 (CVSS score: 2.7) — an insufficient logging vulnerability in VMware ESX that Broadcom says a malicious administrator can exploit to perform certain operations without them being logged. Fixes for this issue are included in the ESXi builds Broadcom published.
The specific fixes, as listed by Broadcom, include:
- CVE-2026-41703 — Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025; VMware ESX ESXi80U3i-25205845; VMware Workstation 26H1; VMware Fusion 26H1; and VMware Cloud Foundation 5.2.3.
- CVE-2026-41709 — Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025; and VMware ESX ESXi80U3j-25429389.
Patched VMware builds and where the fixes appear
Broadcom’s advisory maps each vulnerability to concrete builds and product branches so administrators can match fixes to deployed versions. For the two vCenter-critical issues (CVE-2026-59309 and CVE-2026-59310) the vendor lists fixes in vSphere/vCenter branches 9.1.x.x and 9.0.x.x, in vCenter 8.0 (8.0 U3k), and in VMware Cloud Foundation 5.x via an async patch. The VMXNET3 escape and the other ESX fixes are tied to specific ESXi build numbers provided above.
Broadcom also stated it has found no evidence to suggest any of these issues have been exploited in the wild.
How technologists, procurement teams, and virtual machine administrators will respond
- Technologists and security teams will be matching installed builds to the fixed versions Broadcom published and prioritizing fixes that address network-accessible vCenter flaws (CVE-2026-59309 and CVE-2026-59310), given their high CVSS ratings and the possibility of authentication bypass or arbitrary code execution.
- Procurement and enterprise infrastructure leads will be tracking the specific build numbers named by Broadcom (for vSphere/vCenter, Cloud Foundation and ESXi builds) to ensure vendor-supplied maintenance and patching workflows capture the listed fixes.
- Virtual machine administrators who operate guest systems using the VMXNET3 virtual network adapter will note Broadcom's characterization of CVE-2026-47876 as a virtual machine escape and will be attentive to the ESXi build updates Broadcom supplied.
Broadcom's advisory provides concrete build-level fixes and a clear statement that it has not seen evidence of exploitation in the wild. The published CVE identifiers, CVSS scores, and the exact affected builds give operators the elements they need to reconcile inventories with available patches and to prioritize updates where network-accessible vCenter services or VMXNET3 are in use.




