Broadcom Patches Critical Vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion
Broadcom has released a series of crucial security updates addressing multiple vulnerabilities across its **VMware** product line, including **ESX**, **vCenter**, **Workstation**, and **Fusion**. Among the patched flaws are three critical vulnerabilities that could allow authentication bypass, arbitrary code execution, and virtual machine escape, posing significant risks to enterprise environments.
Broadcom has issued urgent security updates to mitigate several vulnerabilities impacting its **VMware** product suite. These patches address critical weaknesses in **VMware ESX**, **vCenter**, **Workstation**, and **Fusion**, which, if exploited, could lead to severe security breaches.

### Critical Flaws Demand Immediate Attention
Three of the identified vulnerabilities are rated as critical, each carrying a **CVSS** score of 9.8:
* **CVE-2026-59309**: An authentication bypass vulnerability in **VMware vCenter**. A malicious actor with network access could exploit this to bypass authentication mechanisms and gain unauthorized access to the system.
* **CVE-2026-59310**: A directory-traversal vulnerability, also in **vCenter**, which could enable a network-accessible attacker to execute arbitrary code on the affected system.
These **vCenter** vulnerabilities have been addressed in:
* **VMware Cloud Foundation**, **VMware vSphere Foundation** versions 9.1.x.x (Fixed in 9.1.0.0300)
* **VMware Cloud Foundation**, **VMware vSphere Foundation** versions 9.0.x.x (Fixed in 9.0.2.0100)
* **VMware vCenter** version 8.0 (Fixed in 8.0 U3k)
* **VMware Cloud Foundation** versions 5.x (Async patch to 8.0 U3k)
### Additional High-Impact Vulnerabilities
**Broadcom** also patched several other significant flaws:
* **CVE-2026-47876** (CVSS score: 9.3): An out-of-bounds write vulnerability in the **VMXNET3** virtual network adapter of **VMware ESX**. This critical flaw, characterized as a virtual machine escape, allows an attacker with local administrative privileges within a virtual machine to execute code on the host system. This has been fixed in **VMware Cloud Foundation** and **VMware vSphere Foundation** versions **ESXi-9.1.0.0200-25557999** and **ESXi-9.0.2.0100-25595025**, and **VMware ESX ESXi80U3k-25595708**.
* **CVE-2026-41703** (CVSS score: 7.6): An out-of-bounds read vulnerability in **VMware ESX**. An attacker with VM deployment privileges could trigger this, potentially leading to information disclosure or a denial-of-service (**DoS**) condition. For **VMware Workstation** and **Fusion**, the impact is limited to information disclosure. Patches are available for **VMware Cloud Foundation** and **VMware vSphere Foundation** versions **ESXi-9.1.0.0-25370933** and **ESXi-9.0.2.0100-25595025**, **VMware ESX ESXi80U3i-25205845**, **VMware Workstation 26H1**, **VMware Fusion 26H1**, and **VMware Cloud Foundation 5.2.3**.
* **CVE-2026-41709** (CVSS score: 2.7): An insufficient logging vulnerability in **VMware ESX**. A malicious administrator could exploit this to perform certain unlogged operations. This has been addressed in **VMware Cloud Foundation** and **VMware vSphere Foundation** versions **ESXi-9.1.0.0-25370933** and **ESXi-9.0.2.0100-25595025**, and **VMware ESX ESXi80U3j-25429389**.
### No Evidence of In-the-Wild Exploitation
While the vulnerabilities are severe, **Broadcom** has stated that there is currently no evidence to suggest these issues have been exploited in the wild. However, the potential for significant impact underscores the importance of prompt patching for all affected systems.