ON
← Back to feed
VMware ESX, vCenter, Workstation and Fusion: updates are closing critical gaps
Germany🏛️ Politics7 days ago

VMware ESX, vCenter, Workstation and Fusion: updates are closing critical gaps

The article reports that critical security vulnerabilities have been identified in several VMware products including ESX, vCenter, Workstation, and Fusion. These flaws could allow malicious actors to bypass authentication, gain unauthorized access, execute arbitrary code, and potentially escalate privileges within virtualized environments. The vulnerabilities include high-risk issues such as CVE-2026-59309 and CVE-2026-59310, both rated as 'critical' with a CVSS score of 9.8. Additionally, there are other high-risk and lower-risk vulnerabilities affecting various components of VMware systems. Broadcom has issued a security advisory and provided updated software packages to address these issues, including versions like ESXi 9.1.0.0200, vCenter, and Cloud Foundation 8.0 U3k. Users are advised to apply these updates to mitigate potential risks.

Broadcom has released critical security updates for several of its VMware products following the discovery of multiple vulnerabilities that could allow attackers to bypass authentication and gain unauthorized access to systems. The flaws affect VMware ESX, vCenter, Workstation, and Fusion, according to a security advisory issued by the company. These vulnerabilities pose serious risks, with some rated as critical on the Common Vulnerability Scoring System (CVSS). The most severe issue involves a flaw in the VMware Directory Service, which allows unauthenticated users to access systems without proper credentials. This vulnerability, identified as CVE-2026-59309, carries a CVSS score of 9.8 and is classified as high risk. Attackers exploiting this weakness can bypass authentication mechanisms entirely, potentially leading to complete system compromise. Another critical vulnerability, CVE-2026-59310, relates to a path traversal flaw in the Syslog Server component. This allows malicious actors to inject and execute arbitrary code remotely, further increasing the potential impact of an exploit. Both issues highlight the need for immediate patching to prevent unauthorized access and remote code execution. A third critical vulnerability affects the virtual network adapter known as VMXNET3 in VMware ESX. This flaw enables local administrators to break out of a virtual machine and gain access to the host system by performing writes outside of allocated memory boundaries. Identified as CVE-2026-47876, this vulnerability has a CVSS score of 9.3 and poses a significant threat to system integrity. Additional high-risk vulnerabilities have been identified, including one that allows attackers with the ability to roll virtual machines to read outside of allocated memory spaces in VMware ESX, Workstation, and Fusion. This could lead to information leakage or denial-of-service attacks, as noted in CVE-2026-41703, which has a CVSS score of 7.6. While many of these vulnerabilities are rated as critical or high risk, there is also a lower-risk issue affecting VMware ESX. This flaw, CVE-2026-41709, allows certain operations to be performed without being logged, giving attackers the opportunity to act covertly within the system. However, due to its low CVSS score of 2.7, this vulnerability presents less of an immediate threat compared to others. Broadcom has provided updated software packages to address these vulnerabilities across affected products. Updated versions include VMware Cloud Foundation and vSphere Foundation 9.1.0.0300 and 9.0.2.0100, along with specific ESXi versions such as ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025. For VMware vCenter and Cloud Foundation 8.0 U3k, additional patches are available under the designation vCenter ESXi80U3k-25595708. For the Telco Cloud Platform and Telco Cloud Infrastructure, Broadcom has published knowledge base articles detailing the necessary steps for correcting these errors. Additionally, updated versions of VMware ESX, ESXi80U3i-25205845, VMware Fusion, Workstation 26H1, and Cloud Foundation 5.2.3 are available to mitigate the risks associated with unauthorized access and denial-of-service attacks. Organizations using these products are strongly advised to apply the latest patches promptly to ensure their systems remain secure against potential exploitation. Failure to update could expose sensitive infrastructure to cyber threats, making timely action essential to maintain operational continuity and data protection.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 957 days ago
VMware ESX, vCenter, Workstation and Fusion: updates are closing critical gaps

The article reports that critical security vulnerabilities have been identified in several VMware products including ESX, vCenter, Workstation, and Fusion. These flaws could allow malicious actors to bypass authentication, gain unauthorized access, execute arbitrary code, and potentially escalate privileges within virtualized environments. The vulnerabilities include high-risk issues such as CVE-2026-59309 and CVE-2026-59310, both rated as 'critical' with a CVSS score of 9.8. Additionally, there are other high-risk and lower-risk vulnerabilities affecting various components of VMware systems. Broadcom has issued a security advisory and provided updated software packages to address these issues, including versions like ESXi 9.1.0.0200, vCenter, and Cloud Foundation 8.0 U3k. Users are advised to apply these updates to mitigate potential risks.

Bias read (Center): The article presents a technical report on cybersecurity vulnerabilities in VMware products without taking a political stance. It focuses on factual information regarding security advisories and software updates, which does not align with any specific ideological perspective. Therefore, the framing,

Why factuality (95): The article accurately reports the critical vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) described in the primary source document, including their CVSS scores and attack vectors. It also mentions additional vulnerabilities (CVE-2026-41703, CVE-2026-41709) that are included in the

Why objectivity (95): The article presents the information in a neutral tone, focusing on the technical aspects of the vulnerabilities and the necessary updates. There is no evident bias or emotional language, and the content remains focused on the facts presented in the primary source.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories