Broadcom has released a security advisory addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. Three of these vulnerabilities, tracked as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, have been given critical severity ratings.
CVE-2026-59309: vCenter Authentication Bypass Vulnerability
This is an authentication bypass vulnerability in VMware vCenter’s VMware Directory Service. The threat actor must have network access to vCenter to exploit this vulnerability. Successful exploitation of the vulnerability may allow an attacker to bypass authentication and gain unauthorized access to the system.
CVE-2026-59310: vCenter Directory Traversal Vulnerability
This is a directory traversal vulnerability in VMware vCenter’s Syslog server. The threat actor must have network access to vCenter to exploit this vulnerability. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code.
CVE-2026-47876: VMXNET3 Out-of-bounds Write Vulnerability
This is an out-of-bounds write vulnerability in VMware ESX’s VMXNET3 virtual network adapter. The threat actor must have local administrative privileges on a virtual machine with a VMXNET3 virtual network adapter to exploit the vulnerability. Successful exploitation of the vulnerability may allow an attacker to execute code on the host.
NOTE: The vulnerability does not affect Non-VMXNET3 virtual adapters.
CVE-2026-41703: Out-of-bounds Read Vulnerability
A threat actor with VM deployment privileges may exploit this out-of-bounds read flaw, potentially leading to information disclosure or, more likely, a Denial-of-Service (DoS) condition of the host process.
On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
CVE-2026-41709: ESX Insufficient Logging Vulnerability
This is an insufficient logging vulnerability in VMware ESX. A malicious administrator may exploit the vulnerability to perform certain operations without them being logged.
Affected Products and Patched Versions
| VMware Product | Component | Version | CVE | Fixed Version |
| VMware Cloud Foundation,
VMware vSphere Foundation |
vCenter | 9.1.x.x | CVE-2026-59309, CVE-2026-59310 | 9.1.0.0300 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
vCenter | 9.0.x.x | CVE-2026-59309, CVE-2026-59310 | 9.0.2.0100 |
| VMware vCenter | N/A | 8.0 | CVE-2026-59309, CVE-2026-59310 | 8.0 U3k |
| VMware Cloud Foundation | vCenter | 5.x | CVE-2026-59309, CVE-2026-59310 | Async patch to 8.0 U3k |
| VMware Telco Cloud Platform | vCenter | 3.0, 4.x, 5.0.x, 5.1.x | CVE-2026-59309, CVE-2026-59310 | KB449886 |
| VMware Telco Cloud Infrastructure | vCenter | 3.0 | CVE-2026-59309, CVE-2026-59310 | KB449886 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.1.x.x | CVE-2026-47876 | ESXi-9.1.0.0200-25557999 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.0.x.x | CVE-2026-47876 | ESXi-9.0.2.0100-25595025 |
| VMware ESX | N/A | 8.0 | CVE-2026-47876 | ESXi80U3k-25595708 |
| VMware Cloud Foundation | ESX | 5.x | CVE-2026-47876 | Async Patching Guide: KB88287 |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | CVE-2026-47876 | KB449886 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.1.x.x | CVE-2026-41703 | ESXi-9.1.0.0-25370933 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.0.x.x | CVE-2026-41703 | ESXi-9.0.2.0100-25595025 |
| VMware ESX | N/A | 8.0 | CVE-2026-41703 | ESXi80U3i-25205845 |
| VMware Workstation | N/A | 25H2 | CVE-2026-41703 | 26H1 |
| VMware Fusion | N/A | 25H2 | CVE-2026-41703 | 26H1 |
| VMware Cloud Foundation | ESX | 5.x | CVE-2026-41703 | 5.2.3 |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | CVE-2026-41703 | KB449886 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.1.x.x | CVE-2026-41709 | ESXi-9.1.0.0-25370933 |
| VMware Cloud Foundation,
VMware vSphere Foundation |
ESX | 9.0.x.x | CVE-2026-41709 | ESXi-9.0.2.0100-25595025 |
| VMware ESX | N/A | 8.0 | CVE-2026-41709 | ESXi80U3j-25429389 |
| VMware Cloud Foundation | ESX | 5.x | CVE-2026-41709 | 5.2.4 |
| VMware Telco Cloud Platform | ESX | 5.0.x, 5.1.x | CVE-2026-41709 | KB449886 |
For more information, please refer to the VMware Advisory (VMSA-2026-0006).
Qualys Detection
Qualys customers can scan their devices with QIDs 388184, 216356, and 216358 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.