Decoding the world of cybersecurity

Critical VMware fixes put vCenter under scrutiny

Broadcom has issued critical VMware updates for vCenter and ESX, including two CVSS 9.8 vCenter vulnerabilities with no workaround.

Critical VMware fixes put vCenter under scrutiny
Summary
  • Broadcom’s VMSA-2026-0006 covers VMware ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and telecom cloud products.
  • CVE-2026-59309 is a vCenter authentication-bypass flaw, while CVE-2026-59310 is a vCenter directory traversal flaw that may allow arbitrary code execution.
  • The affected products underpin private cloud, telecoms, hosting, and regulated environments, making patching an infrastructure resilience priority.

Broadcom has issued a critical VMware security advisory fixing multiple vulnerabilities across VMware ESX, vCenter, Workstation, Fusion, VMware Cloud Foundation, VMware vSphere Foundation, and telecom cloud products.

The advisory, VMSA-2026-0006, was published on 29 July 2026 and carries a CVSS range of 2.7 to 9.8. The two most severe issues affect vCenter. CVE-2026-59309 is an authentication-bypass vulnerability in VMware Directory Service, while CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server that may allow arbitrary code execution.

Both vCenter flaws have a maximum CVSSv3 base score of 9.8 and no workaround. Broadcom has listed fixed versions across VMware Cloud Foundation, VMware vSphere Foundation, and VMware vCenter. The advisory also covers CVE-2026-47876, a critical out-of-bounds write issue in the VMXNET3 virtual network adapter in ESX, which could allow code execution on the host where an attacker has local administrative privileges on a virtual machine.

The absence of a workaround puts pressure on virtualisation teams to patch quickly, especially where vCenter can be reached from broad internal networks or managed through shared administrative paths. Even without public evidence of exploitation, the severity and placement of the affected components make the update operationally significant.

vCenter occupies a privileged position inside enterprise infrastructure. It manages hosts, clusters, virtual machines, templates, networking, storage integrations, and administrative workflows. A compromise at that layer can move the incident from one workload to the infrastructure used to create, restore, move, and govern many workloads.

The exposure is particularly relevant for private cloud, hosting, telecoms, managed service, and regulated-sector environments. In those settings, virtualisation platforms are not background plumbing; they are the control plane for production services, recovery environments, internal platforms, and security tooling.

European organisations also have a lifecycle-management challenge around VMware estates. Licensing, support, outsourcing, and legacy deployment issues can slow emergency patching when fixes touch infrastructure used across several business services. Asset ownership and contractual clarity become part of the security response when virtualisation platforms are affected by critical flaws.

Patch deployment should be accompanied by a review of vCenter exposure, privileged access, management-network segmentation, backups, logging, and recovery procedures. Where patching cannot be immediate, access to management interfaces should be narrowed and authentication activity reviewed closely. Virtualisation platforms concentrate technical power, and a loss of confidence in that layer can complicate containment, restoration, and assurance long after the patch is installed.

×