Skip to content

Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape

Share
Source: Badtech.org

Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical.

They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication bypass rated CVSS 9.8, and that Broadcom also fixed CVE-2026-59310, a critical directory traversal flaw in the Syslog Server component that can lead to remote code execution over the network. vCenter is VMware’s centralized management platform for ESXi hosts and virtual machines.

The same reporting said Broadcom patched CVE-2026-47876, a critical flaw in the ESXi VMXNET3 virtual network adapter that could let an attacker with administrative privileges inside a guest VM execute code on the ESXi host. That creates a guest-to-host escalation path in shared infrastructure. Security Affairs and Mallory.ai said Broadcom was not aware of in-the-wild exploitation and urged customers to apply updates.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org