{"id":2089,"date":"2026-07-29T17:11:59","date_gmt":"2026-07-29T17:11:59","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2089"},"modified":"2026-07-29T17:11:59","modified_gmt":"2026-07-29T17:11:59","slug":"three-critical-vmware-flaws-allow-auth-bypass-code-execution-and-vm-escape","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2089","title":{"rendered":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 29, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgLKz0u1mJIVvPAxiFFqsvkMVXxyXqS_paYhbtTRFLoIWyl5Q_FwIrJjruxEYH0LAdzJm38P48m_T_24ycKfjPs2bg6FUoy2IWVUxH7SpNtiSJuExOy3dDEAWprGwkvhY5005OPyFUzl2qJzAztAckgZNLVzqlp34s9HtQ3wrvq6lDCcXgYwfOXKF08wtdp\/s1700-e365\/vmware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Broadcom has <a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/38017\" target=\"_blank\">released<\/a> security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.<\/p>\n<p>The first of the three critical-rated flaws is <strong>CVE-2026-59309<\/strong> (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.<\/p>\n<p>\u00abA malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system,\u00bb Broadcom said.<\/p>\n<p>The second critical flaw is a directory-traversal vulnerability in vCenter (<strong>CVE-2026-59310<\/strong>, CVSS score: 9.8) that a malicious actor with network access can exploit to execute arbitrary code. Both vulnerabilities have been addressed in the versions below &#8211;<\/p>\n<ul>\n<li>VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x     (Fixed in 9.1.0.0300)<\/li>\n<li>VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x     (Fixed in 9.0.2.0100)<\/li>\n<li>VMware vCenter version 8.0 (Fixed in 8.0 U3k)<\/li>\n<li>VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Also patched by Broadcom are three other flaws &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-47876<\/strong> (CVSS score: 9.3) &#8211; An out-of-bounds write vulnerability in the VMXNET3 virtual network adapter of VMware ESX that a malicious actor with local administrative privileges on a virtual machine can exploit to execute code on the host. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)<\/li>\n<li><strong>CVE-2026-41703<\/strong> (CVSS score: 7.6) &#8211; An out-of-bounds read vulnerability in VMware ESX that a malicious actor with VM deployment privileges could trigger, potentially leading to information disclosure or a denial-of-service (DoS) condition. On VMware Workstation and Fusion, the impact is limited to information disclosure. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)<\/li>\n<li><strong>CVE-2026-41709<\/strong> (CVSS score: 2.7) &#8211; An insufficient logging vulnerability in VMware ESX that a malicious administrator can exploit to perform certain operations without them being logged. (Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389)<\/li>\n<\/ul>\n<p>Broadcom noted that it has found no evidence to suggest any of these issues have been exploited in the wild. The technology giant also characterized CVE-2026-47876 as a virtual machine escape.<\/p>\n<p>\u00abAn attacker who already holds local administrative privileges inside a virtual machine that uses the VMXNET3 virtual network adapter may execute code on the ESX host,\u00bb it <a href=\"https:\/\/github.com\/vmware\/vcf-security-and-compliance-guidelines\/tree\/main\/security-advisories\/vmsa-2026-0006\" target=\"_blank\">said<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 29, 2026Vulnerability \/ Enterprise Security Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2090,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1672,394,10,58,1349,13,11,409],"class_list":["post-2089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-auth","tag-bypass","tag-code","tag-critical","tag-escape","tag-execution","tag-flaws","tag-vmware"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2089"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2089\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2090"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}