Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Critical VMware vCenter and ESX Flaws Fixed
Jul 30, 2026
5 Mins Read
Moon

Critical VMware vCenter and ESX Flaws Fixed

Broadcom has released a new VMware advisory, VMSA-2026-0006, addressing five vulnerabilities in VMware vCenter, ESX, Workstation, Fusion, and related VMware Cloud Foundation, vSphere Foundation, and Telco Cloud platforms.

The highest priorities are three critical vulnerabilities: CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876. The two vCenter flaws are especially urgent because Broadcom describes them as network-reachable issues that may allow authentication bypass or arbitrary code execution.

What Is VMSA-2026-0006?

VMSA-2026-0006 covers five privately reported VMware vulnerabilities. They affect the VMware Directory Service, vCenter Syslog server, VMXNET3 virtual network adapter, ESX processing, and ESX logging. Broadcom says there are no workarounds, so remediation depends on applying the fixed versions listed in its response matrix.

The advisory applies to standalone deployments and products that include vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Which VMware Vulnerabilities Should Teams Prioritize?

CVE Component Severity Why it matters
CVE-2026-59309 vCenter Directory Service Critical, 9.8 Network attacker may bypass authentication
CVE-2026-59310 vCenter Syslog server Critical, 9.8 Network attacker may execute arbitrary code
CVE-2026-47876 ESX VMXNET3 adapter Critical, 9.3 Potential VM escape from a privileged guest
CVE-2026-41703 ESX, Workstation, Fusion Important / Low Information disclosure or host-process DoS
CVE-2026-41709 ESX logging Low, 2.7 Certain admin actions may not be logged

The practical patch order should start with exposed or broadly reachable vCenter instances, then move to ESX/ESXi hosts where VMXNET3 exposure increases host-level risk.

What Are CVE-2026-59309 and CVE-2026-59310 in VMware vCenter?

CVE-2026-59309 is an authentication bypass vulnerability in the VMware Directory Service. Broadcom says an attacker with network access to VMware vCenter may exploit the issue to bypass authentication and gain unauthorized access.

CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server. Broadcom says an attacker with network access to vCenter may exploit the flaw to execute arbitrary code.

Both vulnerabilities are fixed in:

Product branch Fixed version
vCenter 8.0 8.0 U3k
vCenter 9.0 9.0.2.0100
vCenter 9.1 9.1.0.0300
VMware Cloud Foundation 5.x Async patch to 8.0 U3k
Telco Cloud Platform / Infrastructure Applicable Broadcom-listed fixes

Because VMware vCenter controls virtual machines, hosts, clusters, and administrative workflows, compromise at this layer can affect the broader virtualization control plane.

What Is CVE-2026-47876?

CVE-2026-47876 is an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter on ESX. Broadcom rates it critical with a CVSS score of 9.3. An attacker with local administrative privileges inside a virtual machine using VMXNET3 may exploit the issue to execute code on the ESX host.

This makes CVE-2026-47876 different from the vCenter flaws. It requires privileged access inside a guest VM, but the potential host impact makes it important in shared, hosted, or multi-tenant environments.

Broadcom says non-VMXNET3 virtual adapters are not affected by this specific issue, but it also advises updating ESX rather than treating adapter changes as the general fix.

Fixed ESX builds include:

ESX branch Fixed build
ESX 8.0 ESXi80U3k-25595708
ESX 9.0 ESXi-9.0.2.0100-25595025
ESX 9.1 ESXi-9.1.0.0200-25557999

What About CVE-2026-41703 and CVE-2026-41709?

CVE-2026-41703 is an out-of-bounds read vulnerability affecting ESX, Workstation, and Fusion. Broadcom rates it Important on ESX with a CVSS score of 7.6, and Low on Workstation and Fusion with a CVSS score of 2.7. Exploitation may lead to information disclosure or, more likely, denial of service in a host process.

CVE-2026-41709 is an insufficient logging vulnerability in ESX. Broadcom rates it Low with a CVSS score of 2.7. A malicious administrator could perform certain operations without those actions being logged, reducing auditability during investigation or compliance review.

These two issues should remain in the remediation plan, but they generally follow the three critical vulnerabilities unless local business risk changes the order.

Is There Active Exploitation or Public PoC?

Broadcom says it has no information to suggest exploitation in the wild for the VMSA-2026-0006 vulnerabilities.

No credible public proof-of-concept or exploit module was identified at the time of writing. Security teams should still reassess this status frequently, since vCenter and ESX vulnerabilities can attract fast researcher and attacker attention after disclosure.

What Should Security Teams Do Now?

Security teams should treat VMSA-2026-0006 as an emergency change, especially where vCenter is reachable from untrusted networks or broad internal segments. Broadcom’s FAQ says the issues qualify as emergency-change candidates and advises prompt organizational action.

Recommended actions include:

  • Patch vCenter first where exposure is highest: Apply 8.0 U3k, 9.0.2.0100, 9.1.0.0300, or the relevant Cloud Foundation / Telco Cloud fix.
  • Update ESX/ESXi hosts: Prioritize hosts running VMs with VMXNET3, especially in shared or multi-tenant environments.
  • Inventory affected products: Include standalone vCenter, ESX, Workstation, Fusion, VCF, vSphere Foundation, and Telco Cloud deployments.
  • Check older environments carefully: Broadcom says vSphere 6.5 and 6.7 should be presumed affected because they are past general support, while vSphere 7 customers need extended-support processes for patches.
  • Review management telemetry: Look for unexpected vCenter authentication activity, Syslog anomalies, unusual administrative sessions, ESX host crashes, and suspicious VM activity before host anomalies.
  • Plan patch sequencing: vCenter Quick Patch is not available for these vCenter updates, while ESX Live Patch may help reduce host-update disruption in supported environments.

How Can SOCRadar Help Prioritize VMware Response?

VMSA-2026-0006 includes two network-reachable critical flaws in vCenter – knowing which instances are internet-facing is as urgent as applying the fix. Teams need to know which vCenter services are exposed, which ESX hosts are most sensitive, and whether exploit activity changes after disclosure.

SOCRadar’s Cyber Threat Intelligence helps teams track critical CVEs, exploit alerts, affected technologies, and new exploitation signals around vulnerabilities such as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876. With its Vulnerability Intelligence capabilities, it provides alerts for new critical vulnerabilities or exploits affecting public-facing services and technologies.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Attack Surface Management (ASM) adds exposure context by helping organizations identify vulnerable software, exposed services, third-party technologies, expired certificates, DNS records, and undiscovered cloud assets. It can also alert when a critical vulnerability is cross-referenced with exposed software assets.

For VMSA-2026-0006, that combination helps teams move faster on the assets that matter most: exposed vCenter systems, high-value ESX clusters, and environments where remediation status is unclear.