Broadcom has released security updates for VMware products after disclosing several serious flaws that could let attackers break out of a virtual machine or take over management servers. The issues include CVE-2026-47876, a critical out-of-bounds write in the ESXi VMXNET3 virtual network adapter that allows a guest with local admin privileges to execute code on the host, plus critical vCenter flaws CVE-2026-59309 (authentication bypass) and CVE-2026-59310 (network-exploitable remote code execution). ESXi, vCenter, Workstation, and Fusion are also affected by CVE-2026-41703, and ESXi by CVE-2026-41709.
Why it matters: Organizations running VMware virtualization or vCenter management systems should treat this as urgent because host compromise or vCenter takeover can expose many systems at once. Apply Broadcom's updates quickly and review internet-exposed or broadly accessible vCenter and ESXi environments first.
Lawrence Abrams
2026.07.30
97% relevant
This article reports the same Broadcom emergency patch release for VMware vCenter, ESX/ESXi, Workstation, and Fusion, and adds patch version details, affected bundled products such as Cloud Foundation and Telco Cloud, operational impact during patching, and the note that there are no workarounds.
Eduard Kovacs
2026.07.29
100% relevant
This article establishes a new tracked event: Broadcom's disclosure and patching of a specific July 2026 set of VMware ESXi, vCenter, Workstation, and Fusion vulnerabilities centered on CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310.
← Back to all stories