importantSYS.SOURCE: The Hacker News• 2026-07-29T21:01:15+05:30
Critical VMware Vulnerabilities Enable Authentication Bypass, Remote Code Execution, and Virtual Machine Escape
Broadcom addressed three critical vulnerabilities in VMware products, including authentication bypass (CVE-2026-59309, CVSS 9.8) and remote code execution (CVE-2026-59310, CVSS 9.8), impacting vCenter, ESX, Workstation, and Fusion. Patched versions are available, with no evidence of active exploitation reported.
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.
"A malicious actor with network access to vCenter
*** END OF TRANSMISSION ***