VMware ESX, vCenter, Workstation, and Fusion Multiple Vulnerabilities

Broadcom has released a security advisory addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. Three of these vulnerabilities, tracked as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, have been given critical severity ratings.

CVE-2026-59309: vCenter Authentication Bypass Vulnerability

This is an authentication bypass vulnerability in VMware vCenter’s VMware Directory Service. The threat actor must have network access to vCenter to exploit this vulnerability. Successful exploitation of the vulnerability may allow an attacker to bypass authentication and gain unauthorized access to the system.

CVE-2026-59310: vCenter Directory Traversal Vulnerability

This is a directory traversal vulnerability in VMware vCenter’s Syslog server. The threat actor must have network access to vCenter to exploit this vulnerability. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code.

CVE-2026-47876: VMXNET3 Out-of-bounds Write Vulnerability

This is an out-of-bounds write vulnerability in VMware ESX’s VMXNET3 virtual network adapter. The threat actor must have local administrative privileges on a virtual machine with a VMXNET3 virtual network adapter to exploit the vulnerability. Successful exploitation of the vulnerability may allow an attacker to execute code on the host. 

NOTE: The vulnerability does not affect Non-VMXNET3 virtual adapters.

CVE-2026-41703: Out-of-bounds Read Vulnerability

A threat actor with VM deployment privileges may exploit this out-of-bounds read flaw, potentially leading to information disclosure or, more likely, a Denial-of-Service (DoS) condition of the host process. 

On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

CVE-2026-41709: ESX Insufficient Logging Vulnerability

This is an insufficient logging vulnerability in VMware ESX. A malicious administrator may exploit the vulnerability to perform certain operations without them being logged.

Affected Products and Patched Versions

VMware Product  Component  Version  CVE  Fixed Version 
VMware Cloud Foundation, 

VMware vSphere Foundation 

vCenter  9.1.x.x  CVE-2026-59309, CVE-2026-59310  9.1.0.0300 
VMware Cloud Foundation, 

VMware vSphere Foundation 

vCenter  9.0.x.x  CVE-2026-59309, CVE-2026-59310  9.0.2.0100 
VMware vCenter  N/A  8.0  CVE-2026-59309, CVE-2026-59310  8.0 U3k 
VMware Cloud Foundation   vCenter  5.x  CVE-2026-59309, CVE-2026-59310  Async patch to 8.0 U3k 
VMware Telco Cloud Platform  vCenter  3.0, 4.x, 5.0.x, 5.1.x  CVE-2026-59309, CVE-2026-59310  KB449886 
VMware Telco Cloud Infrastructure  vCenter  3.0  CVE-2026-59309, CVE-2026-59310  KB449886 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.1.x.x  CVE-2026-47876  ESXi-9.1.0.0200-25557999 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.0.x.x  CVE-2026-47876  ESXi-9.0.2.0100-25595025 
VMware ESX  N/A  8.0  CVE-2026-47876  ESXi80U3k-25595708 
VMware Cloud Foundation   ESX  5.x  CVE-2026-47876  Async Patching Guide: KB88287 
VMware Telco Cloud Platform  ESX  5.0.x, 5.1.x  CVE-2026-47876  KB449886 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.1.x.x  CVE-2026-41703  ESXi-9.1.0.0-25370933 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.0.x.x  CVE-2026-41703  ESXi-9.0.2.0100-25595025 
VMware ESX  N/A  8.0  CVE-2026-41703  ESXi80U3i-25205845 
VMware Workstation  N/A  25H2   CVE-2026-41703  26H1 
VMware Fusion  N/A  25H2  CVE-2026-41703  26H1 
VMware Cloud Foundation   ESX  5.x  CVE-2026-41703  5.2.3
VMware Telco Cloud Platform  ESX  5.0.x, 5.1.x  CVE-2026-41703  KB449886 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.1.x.x  CVE-2026-41709  ESXi-9.1.0.0-25370933 
VMware Cloud Foundation, 

VMware vSphere Foundation 

ESX  9.0.x.x  CVE-2026-41709  ESXi-9.0.2.0100-25595025 
VMware ESX  N/A  8.0  CVE-2026-41709  ESXi80U3j-25429389 
VMware Cloud Foundation   ESX  5.x  CVE-2026-41709  5.2.4 
VMware Telco Cloud Platform  ESX  5.0.x, 5.1.x  CVE-2026-41709  KB449886 

For more information, please refer to the VMware Advisory (VMSA-2026-0006).

Qualys Detection

Qualys customers can scan their devices with QIDs 388184, 216356, and 216358 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Author: Diksha Ojha

Senior Technical Writer

Leave a Reply

Your email address will not be published. Required fields are marked *