T

Threats

VMware vCenter and ESX Critical Vulnerabilities

Overview

  • CVE: CVE-2026-59309, CVE-2026-59310, CVE-2026-47876

  • Severity: Critical

  • CVSS: 9.8, 9.8 and 9.3 respectively

  • Affected components: VMware vCenter and VMware ESX


Broadcom published VMware Security Advisory VMSA-2026-0006 on 29 July 2026. The advisory addresses three critical vulnerabilities affecting VMware vCenter and ESX components used across VMware Cloud Foundation, VMware vSphere Foundation and VMware Telco Cloud platforms.

The highest-rated issues, CVE-2026-59309 and CVE-2026-59310, have CVSS v3.1 scores of 9.8. Both can be exploited by an unauthenticated malicious actor with network access to vCenter. CVE-2026-47876, scored 9.3, can allow a malicious actor with local administrative privileges in a VM using VMXNET3 to execute code on the ESX host.

Broadcom has provided patches and states that no workarounds are available. Organisations should treat deployment as an emergency change and update affected systems promptly.


Affected Versions

VMware vCenter - CVE-2026-59309 and CVE-2026-59310

Product / branch

Affected versions

Fixed release

Source

VMware Cloud Foundation / vSphere Foundation vCenter 9.1

9.1.x.x before the applicable fixed release

9.1.0.0300 (CVE-2026-59309 was first addressed in 9.1.0.0200; 9.1.0.0300 is the current cumulative release)

VMSA-2026-0006 response matrix

VMware Cloud Foundation / vSphere Foundation vCenter 9.0

9.0.x.x before 9.0.2.0100

9.0.2.0100

VMSA-2026-0006 response matrix

VMware vCenter 8.0

Before 8.0 U3k

8.0 U3k, build 25600417

vCenter 8.0 U3k release notes

VMware Cloud Foundation 5.x

All 5.x deployments

Asynchronous patch to vCenter 8.0 U3k via the vendor's asynchronous patching process

VMSA-2026-0006 response matrix

VMware Telco Cloud Platform 3.0, 4.x, 5.0.x, 5.1.x and Telco Cloud Infrastructure 3.0

All listed versions

Product-specific update documented in Broadcom KB449886

VMSA-2026-0006 response matrix


VMware ESX - CVE-2026-47876

Product / branch

Affected versions

Fixed build

Source

VMware Cloud Foundation / vSphere Foundation ESX 9.1

9.1.x.x before ESXi-9.1.0.0200-25557999

ESXi-9.1.0.0200-25557999

VMSA-2026-0006 response matrix

VMware Cloud Foundation / vSphere Foundation ESX 9.0

9.0.x.x before ESXi-9.0.2.0100-25595025

ESXi-9.0.2.0100-25595025

VMSA-2026-0006 response matrix

VMware ESX 8.0

Before ESXi 8.0 U3k

ESXi80U3k-25595708

ESXi 8.0 U3k release notes

VMware Cloud Foundation ESX 5.x

All 5.x deployments

Vendor's asynchronous patch via the VMware Cloud Foundation 5.x asynchronous patching process

VMSA-2026-0006 response matrix

VMware Telco Cloud Platform ESX 5.0.x and 5.1.x

All listed versions

Product-specific update documented in Broadcom KB449886

VMSA-2026-0006 response matrix


Vulnerability Breakdown

CVE-2026-59309 - vCenter Authentication Bypass

  • Severity: Critical

  • CVSS: 9.8

  • Description: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

  • Impact: A malicious actor may bypass authentication and gain unauthorised access to vCenter.

  • Conditions: Network access to the affected vCenter is required. No prior authentication is required.

  • Mitigation: Apply the fixed vCenter version listed for the deployed product branch. No workaround is available.


CVE-2026-59310 - vCenter Directory Traversal

  • Severity: Critical

  • CVSS: 9.8

  • Description: VMware vCenter contains a directory traversal vulnerability in the Syslog server.

  • Impact: A malicious actor may execute arbitrary code on the affected system.

  • Conditions: Network access to the affected vCenter is required. No prior authentication is required.

  • Mitigation: Apply the fixed vCenter version listed for the deployed product branch. No workaround is available.


CVE-2026-47876 - VMXNET3 Out-of-Bounds Write

  • Severity: Critical

  • CVSS: 9.3

  • Description: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.

  • Impact: A malicious actor may execute code on the ESX host, resulting in a VM escape.

  • Conditions: The actor must have local administrative privileges in a virtual machine that uses a VMXNET3 virtual network adapter.

  • Notes: Virtual machines using other virtual network adapters are not affected by this vulnerability.

  • Mitigation: Apply the fixed ESX build listed for the deployed product branch. No workaround is available.


Mitigation

  • Identify VMware vCenter and ESX versions and builds across the environment.

  • Apply the fixed versions in Broadcom VMSA-2026-0006. Patches are cumulative and do not require prior patches.

  • Treat remediation as an emergency change. Prioritise the unauthenticated vCenter vulnerabilities, while planning ESX host updates in parallel where compatibility permits.

  • Use vMotion or a rolling reboot process for ESX hosts where supported. VMware advises that an ESX update requires a host restart, although supported live-patch options may reduce disruption.

  • Follow the vendor's asynchronous or product-specific patching instructions for VMware Cloud Foundation 5.x and VMware Telco Cloud products.

  • Do not rely on changing VMXNET3 adapters as a general mitigation. Broadcom advises updating ESX.


Summary for IT Teams

  • Products: VMware vCenter and VMware ESX within VMware Cloud Foundation, VMware vSphere Foundation and supported VMware Telco Cloud platforms

  • Threat Level: Critical, maximum CVSS 9.8

  • Action Required: Inventory affected deployments and apply the fixed vCenter and ESX releases immediately. No vendor workaround is available.


Reference


Need Help?

If your organisation needs assistance assessing exposure or deploying VMware updates, contact the Secure ISS SOC on 1300 769 460 or soc@secure-iss.com.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.