Broadcom patches vulnerabilities all over VMware

Wait 5 sec.

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud InfrastructureCVE-206-59309 affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication when accessing vCenter.The next vulnerability, CVE-2026-47876, is an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter that could enable bad actors to execute code on the host. This does not affect non-VMXNET3 virtual adapters.CVE-2026-59310 affects VMware vCenter’s Syslog server that a malicious actor with network access could use to execute arbitrary code.The fourth issue, CVE-2026-41703, is rated high, rather than critical, and concerns multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or a denial-of-service (DoS) condition in the host process.Last, and least critical, is CVE-2026-41709: VMware ESX has insufficient logging capabilities, potentially enabling a malicious administrator to do things without being caught.Patches for all these vulnerabilities can be found in Broadcom’s VMSA-2026-0006 security advisory.