Security · 1h ago
VMware Patches Critical Auth Bypass, Code Execution, and VM Escape Flaws
Broadcom released fixes for three critical VMware vulnerabilities affecting ESX, vCenter, Workstation, and Fusion. CVE-2026-59309 is a vCenter authentication bypass with a CVSS score of 9.8, allowing network-based attackers to gain access. The other critical flaws enable code execution and VM escape, posing severe risks to virtualized environments.
Meridian48 take
While patches are available, the breadth of affected products and the severity of the flaws—especially the auth bypass—mean organizations should prioritize updates immediately.
Read the full reporting
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape →
The Hacker News
vmwarevulnerability