T
Threats
VMware vCenter and ESX Critical Vulnerabilities
Overview
CVE: CVE-2026-59309, CVE-2026-59310, CVE-2026-47876
Severity: Critical
CVSS: 9.8, 9.8 and 9.3 respectively
Affected components: VMware vCenter and VMware ESX
Broadcom published VMware Security Advisory VMSA-2026-0006 on 29 July 2026. The advisory addresses three critical vulnerabilities affecting VMware vCenter and ESX components used across VMware Cloud Foundation, VMware vSphere Foundation and VMware Telco Cloud platforms.
The highest-rated issues, CVE-2026-59309 and CVE-2026-59310, have CVSS v3.1 scores of 9.8. Both can be exploited by an unauthenticated malicious actor with network access to vCenter. CVE-2026-47876, scored 9.3, can allow a malicious actor with local administrative privileges in a VM using VMXNET3 to execute code on the ESX host.
Broadcom has provided patches and states that no workarounds are available. Organisations should treat deployment as an emergency change and update affected systems promptly.
Affected Versions
VMware vCenter - CVE-2026-59309 and CVE-2026-59310
Product / branch | Affected versions | Fixed release | Source |
|---|---|---|---|
VMware Cloud Foundation / vSphere Foundation vCenter 9.1 | 9.1.x.x before the applicable fixed release | 9.1.0.0300 (CVE-2026-59309 was first addressed in 9.1.0.0200; 9.1.0.0300 is the current cumulative release) | |
VMware Cloud Foundation / vSphere Foundation vCenter 9.0 | 9.0.x.x before 9.0.2.0100 | 9.0.2.0100 | |
VMware vCenter 8.0 | Before 8.0 U3k | 8.0 U3k, build 25600417 | |
VMware Cloud Foundation 5.x | All 5.x deployments | Asynchronous patch to vCenter 8.0 U3k via the vendor's asynchronous patching process | |
VMware Telco Cloud Platform 3.0, 4.x, 5.0.x, 5.1.x and Telco Cloud Infrastructure 3.0 | All listed versions | Product-specific update documented in Broadcom KB449886 |
VMware ESX - CVE-2026-47876
Product / branch | Affected versions | Fixed build | Source |
|---|---|---|---|
VMware Cloud Foundation / vSphere Foundation ESX 9.1 | 9.1.x.x before ESXi-9.1.0.0200-25557999 | ESXi-9.1.0.0200-25557999 | |
VMware Cloud Foundation / vSphere Foundation ESX 9.0 | 9.0.x.x before ESXi-9.0.2.0100-25595025 | ESXi-9.0.2.0100-25595025 | |
VMware ESX 8.0 | Before ESXi 8.0 U3k | ESXi80U3k-25595708 | |
VMware Cloud Foundation ESX 5.x | All 5.x deployments | Vendor's asynchronous patch via the VMware Cloud Foundation 5.x asynchronous patching process | |
VMware Telco Cloud Platform ESX 5.0.x and 5.1.x | All listed versions | Product-specific update documented in Broadcom KB449886 |
Vulnerability Breakdown
CVE-2026-59309 - vCenter Authentication Bypass
Severity: Critical
CVSS: 9.8
Description: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.
Impact: A malicious actor may bypass authentication and gain unauthorised access to vCenter.
Conditions: Network access to the affected vCenter is required. No prior authentication is required.
Mitigation: Apply the fixed vCenter version listed for the deployed product branch. No workaround is available.
CVE-2026-59310 - vCenter Directory Traversal
Severity: Critical
CVSS: 9.8
Description: VMware vCenter contains a directory traversal vulnerability in the Syslog server.
Impact: A malicious actor may execute arbitrary code on the affected system.
Conditions: Network access to the affected vCenter is required. No prior authentication is required.
Mitigation: Apply the fixed vCenter version listed for the deployed product branch. No workaround is available.
CVE-2026-47876 - VMXNET3 Out-of-Bounds Write
Severity: Critical
CVSS: 9.3
Description: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.
Impact: A malicious actor may execute code on the ESX host, resulting in a VM escape.
Conditions: The actor must have local administrative privileges in a virtual machine that uses a VMXNET3 virtual network adapter.
Notes: Virtual machines using other virtual network adapters are not affected by this vulnerability.
Mitigation: Apply the fixed ESX build listed for the deployed product branch. No workaround is available.
Mitigation
Identify VMware vCenter and ESX versions and builds across the environment.
Apply the fixed versions in Broadcom VMSA-2026-0006. Patches are cumulative and do not require prior patches.
Treat remediation as an emergency change. Prioritise the unauthenticated vCenter vulnerabilities, while planning ESX host updates in parallel where compatibility permits.
Use vMotion or a rolling reboot process for ESX hosts where supported. VMware advises that an ESX update requires a host restart, although supported live-patch options may reduce disruption.
Follow the vendor's asynchronous or product-specific patching instructions for VMware Cloud Foundation 5.x and VMware Telco Cloud products.
Do not rely on changing VMXNET3 adapters as a general mitigation. Broadcom advises updating ESX.
Summary for IT Teams
Products: VMware vCenter and VMware ESX within VMware Cloud Foundation, VMware vSphere Foundation and supported VMware Telco Cloud platforms
Threat Level: Critical, maximum CVSS 9.8
Action Required: Inventory affected deployments and apply the fixed vCenter and ESX releases immediately. No vendor workaround is available.
Reference
Need Help?
If your organisation needs assistance assessing exposure or deploying VMware updates, contact the Secure ISS SOC on 1300 769 460 or soc@secure-iss.com.

