VMware fixes three critical flaws allowing auth bypass, VM escapes
AI Summary
VMware, now under Broadcom, has released emergency security updates to address five vulnerabilities in vCenter, ESX, Workstation, and Fusion, including three critical flaws. CVE-2026-59309 and CVE-2026-59310 are critical authentication bypass and arbitrary code execution vulnerabilities in vCenter that can be exploited by unauthenticated attackers with network access. CVE-2026-47876 is a critical VM escape vulnerability in the VMXNET3 virtual network adapter, allowing a guest VM attacker with local admin privileges to execute code on the host. While there is no evidence of active exploitation, VMware servers are high-value targets for ransomware and advanced threat actors, and these flaws could enable broad lateral movement and persistence if left unpatched.
AI-extracted · verify before operational use