Broadcom released VMSA-2026-0006 to patch five vulnerabilities affecting VMware vCenter, ESXi, Workstation, and Fusion, including three critical flaws. The most severe issues are CVE-2026-59309 and CVE-2026-59310, both rated CVSS 9.8, which can be exploited remotely against vCenter by an unauthenticated attacker with network access to bypass authentication or achieve remote code execution. Broadcom said there are no workarounds and urged organizations to prioritize patching, particularly for externally reachable or broadly accessible vCenter deployments.
The advisory also fixes CVE-2026-47876, a critical VM escape in ESXi’s VMXNET3 virtual network adapter that could let an attacker with local administrative privileges inside a guest VM execute arbitrary code on the ESXi host. Two additional flaws were patched: CVE-2026-41703, a high-severity issue affecting ESXi, Workstation, and Fusion that can cause information disclosure or, more likely, denial of service, and CVE-2026-41709, a low-severity ESXi logging-related bug. Broadcom said it is not aware of in-the-wild exploitation and published patching guidance and an FAQ for affected customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In its advisory materials, Broadcom said it was not aware of in-the-wild exploitation of the patched vulnerabilities. The company also urged organizations to prioritize installing updates and published FAQ guidance on impact and patching requirements.
Broadcom published security advisory VMSA-2026-0006 covering five vulnerabilities affecting VMware vCenter, ESXi, Workstation, and Fusion, and released patches for the issues. The advisory includes three critical flaws: CVE-2026-47876 in ESXi VMXNET3, CVE-2026-59309 in vCenter authentication, and CVE-2026-59310 in vCenter remote code execution.
VMware published remediation guidance for VMware Telco Cloud Platform and VMware Telco Cloud Infrastructure in response to VMSA-2026-0006. The notice identified affected Telco Cloud versions, listed the five CVEs involved, and directed customers to fixed vCenter and ESX/ESXi versions or to support for upgrade and mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
22 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcecyberveille.ch
Open sourcecsoonline.com
Open sourcemalware.news
Open sourcevmware.com
Open sourcesdxcentral.com
Open sourcerunzero.com
Open sourceknowledge.broadcom.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.