Skip to content

Broadcom patches critical VMware vCenter and ESXi flaws including auth bypass, RCE, and VM escape

Share
Source: Badtech.org

Security Affairs, Mallory.ai, and Field Effect reported that Broadcom released patches on July 29 for five VMware vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including three rated critical.

They said the most severe issue, CVE-2026-59309, is a critical vCenter authentication bypass rated CVSS 9.8, and that Broadcom also fixed CVE-2026-59310, a critical directory traversal flaw in the Syslog Server component that can lead to remote code execution over the network. vCenter is VMware’s centralized management platform for ESXi hosts and virtual machines.

The same reporting said Broadcom patched CVE-2026-47876, a critical flaw in the ESXi VMXNET3 virtual network adapter that could let an attacker with administrative privileges inside a guest VM execute code on the ESXi host. That creates a guest-to-host escalation path in shared infrastructure. Security Affairs and Mallory.ai said Broadcom was not aware of in-the-wild exploitation and urged customers to apply updates.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope. The most urgent

By Adam Field Source: Badtech.org