hacker-news · Crawled Jul 29, 2026
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Read original article ↗AI Summary
Broadcom has patched multiple critical vulnerabilities in VMware products, including VMware ESX, vCenter, Workstation, and Fusion. The most severe flaws include CVE-2026-59309, an authentication bypass in vCenter that allows unauthorized access, and CVE-2026-59310, a directory traversal flaw enabling remote code execution. Additionally, CVE-2026-47876 is a critical VM escape vulnerability in the VMXNET3 adapter, allowing a malicious actor with local VM privileges to execute code on the host. No evidence of in-the-wild exploitation has been found so far.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.