> ## Content Index
> Fetch the complete content index at: https://badtech.org/llms.txt
> Use this file to discover other available public pages before exploring further.

# Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape
- URL: https://badtech.org/broadcom-patches-critical-vmware-vcenter-and-esxi-flaws-including-auth-bypass-rce-and-vm-escape/
- Published: 2026-07-31T01:06:59.000Z
- Updated: 2026-07-31T01:06:59.000Z
- Author: Adam Field
- Tags: Radar, Vulnerabilities

Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical.

They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication bypass rated CVSS 9.8, and that Broadcom also fixed CVE-2026-59310, a critical directory traversal flaw in the Syslog Server component that can lead to remote code execution over the network. vCenter is VMware’s centralized management platform for ESXi hosts and virtual machines.

The same reporting said Broadcom patched CVE-2026-47876, a critical flaw in the ESXi VMXNET3 virtual network adapter that could let an attacker with administrative privileges inside a guest VM execute code on the ESXi host. That creates a guest-to-host escalation path in shared infrastructure. Security Affairs and Mallory.ai said Broadcom was not aware of in-the-wild exploitation and urged customers to apply updates.

## Sources

- [Security Affairs: Broadcom Patches Critical ESXi Vulnerability Enabling Host Code Execution](https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html?ref=badtech.org)
- [Mallory.ai: Broadcom Patches Critical VMware vCenter RCE and ESXi ...](https://mallory.ai/stories/019fadc6-a54b-7cc9-8315-02e81f66169a?ref=badtech.org)
- [Field Effect: Broadcom Patches Critical Vulnerabilities Affecting Multiple VMware Products](https://fieldeffect.com/blog/broadcom-patches-critical-vcenter-vulnerabilities?ref=badtech.org)