VMware Flaws

Overview

Broadcom has released urgent security updates for VMware ESX, vCenter, Workstation, and Fusion, addressing multiple vulnerabilities — three of which are rated critical. These flaws include authentication bypass, directory traversal leading to code execution, and a VM escape that could allow attackers to break out of virtual machines and compromise the host.

Critical Vulnerabilities

  1. CVE‑2026‑59309 (CVSS 9.8)
    • Authentication bypass in vCenter.
    • Exploitable by malicious actors with network access to gain unauthorized system access.
  2. CVE‑2026‑59310 (CVSS 9.8)
    • Directory traversal in vCenter.
    • Allows arbitrary code execution via crafted requests.
  3. CVE‑2026‑47876 (CVSS 9.3)
    • Out‑of‑bounds write in VMXNET3 virtual network adapter.
    • Exploitable by attackers with local admin privileges inside a VM to execute code on the ESX host — a VM escape scenario.

Other Patched Flaws

  • CVE‑2026‑41703 (CVSS 7.6)
    • Out‑of‑bounds read in ESX.
    • Could lead to information disclosure or DoS.
    • On Workstation/Fusion, limited to information disclosure.
  • CVE‑2026‑41709 (CVSS 2.7)
    • Insufficient logging in ESX.
    • Allows malicious administrators to perform operations without logs.

Impacted Versions & Fixes

  • VMware Cloud Foundation / vSphere Foundation 9.1.x.x → Fixed in 9.1.0.0300
  • VMware Cloud Foundation / vSphere Foundation 9.0.x.x → Fixed in 9.0.2.0100
  • VMware vCenter 8.0 → Fixed in 8.0 U3k
  • VMware ESX → Fixed in ESXi‑9.1.0.0200‑25557999, ESXi‑9.0.2.0100‑25595025, ESXi80U3k‑25595708
  • VMware Workstation & Fusion → Fixed in 26H1 releases

Broadcom confirmed no evidence of exploitation in the wild so far, but emphasized the urgency of patching.

Defensive Guidance

Organizations should:

  • Apply patches immediately across ESX, vCenter, Workstation, and Fusion.
  • Restrict network access to management interfaces.
  • Audit logs for anomalies, especially missing entries tied to CVE‑2026‑41709.
  • Monitor VM activity for signs of VM escape exploitation.

Expert in the Cloud Insight

These vulnerabilities highlight the high‑value target status of VMware environments. Authentication bypass and directory traversal flaws expose management planes, while VM escape attacks threaten the very foundation of virtualization security. For enterprises, the takeaway is clear: patching is non‑negotiable, management interfaces must be locked down, and monitoring must extend to both host and guest activity.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.