ZeroHour
Security Affairspublished ()ingested @securityaffairs

Broadcom Patches Critical ESXi Vulnerability Enabling Host Code Execution

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41703
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability.

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

NVD description · AI analysis pending
7.6<1%
CVE-2026-41709
VMware ESX contains an insufficient logging vulnerability.

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

NVD description · AI analysis pending
2.7<1%
CVE-2026-47876
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

NVD description · AI analysis pending
9.3<1%
CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

NVD description · AI analysis pending
9.88%
  • vmware vcenter server
CVE-2026-59310
Unauthenticated Path Traversal RCE in Broadcom VMware vCenter Server Syslog

CVE-2026-59310 is a directory traversal (CWE-22) vulnerability in the Syslog server component of VMware vCenter Server, rated critical at CVSS 9.8. It can be triggered over the network without authentication or user interaction, allowing a malicious actor with network access to vCenter to achieve arbitrary code execution. An attacker who exploits it gains code execution on the vCenter appliance, and reported campaigns show it has been used to establish persistent remote access and, by a suspected China-nexus actor, to deploy Babuk ransomware. Any organization running an affected version of vCenter Server is exposed, especially where the management interface is reachable from the internet; the available data does not specify affected version ranges. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-08-18, it was reportedly exploited just five days after disclosure, and EPSS estimates a 45.9% probability of exploitation within 30 days (99th percentile).

Do: Upgrade vCenter Server to the patched release identified in Broadcom's advisory (no specific version ranges are provided in this data) and prioritize any vCenter that is internet-facing, in line with CISA KEV and BOD 26-04 requirements for federal agencies. Until patched, restrict access to the vCenter management interface to trusted networks and verify whether the vCenter Syslog server is enabled. Hunt for compromise indicators, including unexplained remote-access persistence and Babuk ransomware artifacts, given the documented China-nexus exploitation.

9.846% KEV ransomware
  • Broadcom (VMware) vCenter Server
largeApproximately 50,000-100,000 internet-exposed vCenter Server instances, with total deployments (including internal-only) likely in the hundreds of thousands
Full article420 words · extracted from securityaffairs.com · click to collapse

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine.

Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a VM escape flaw in the VMXNET3 virtual network adapter. An attacker with administrator privileges inside a virtual machine could exploit it to execute arbitrary code on the underlying ESXi host.

“VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.” reads the advisory. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.”

Broadcom also fixed a critical vCenter authentication bypass, tracked as CVE-2026-59309 (CVSSv3 base score of 9.8), that can be exploited to gain unauthorized access to the targeted system.

“VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory. “A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.”

The third critical issue fixed by the company is CVE-2026-59310 (CVSSv3 base score of 9.8), a flaw allowing an attacker with network access to execute arbitrary code. 

“VMware vCenter contains a directory traversal vulnerability in the Syslog server. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.”states the advisory.”A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.”

The vendor also patched CVE-2026-41703 (CVSSv3 score of 7.6), a high-severity flaw affecting VMware ESXi, Workstation, and Fusion that could allow an attacker with VM deployment permissions to disclose information or cause a denial-of-service on the host. Another issue, CVE-2026-41709 (CVSSv3 score of 7.6), lets an administrator perform certain actions on ESXi without logging in. Although no active exploitation has been reported, Broadcom urges customers to apply the updates promptly.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, virtual machine)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html