Multiple security vulnerabilities have been identified in VMware ESX, vCenter, Workstation, and Fusion. The overall risk/impact is high due to the critical-rated flaws allowing authentication bypass, code execution, and VM escape.
CVE-2026-59309 (CVSS 9.8 — Severity): An authentication bypass vulnerability in VMware vCenter that a malicious actor with network access can exploit to gain unauthorized access to the system.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in VMware ESX, vCenter, Workstation, and Fusion. The overall risk/impact is high due to the critical-rated flaws allowing authentication bypass, code execution, and VM escape.
CVE-2026-59309 (CVSS 9.8 — Severity): An authentication bypass vulnerability in VMware vCenter that a malicious actor with network access can exploit to gain unauthorized access to the system.[emaillocker id="1283"]
CVE-2026-59310 (CVSS 9.8 — Severity): A directory-traversal vulnerability in vCenter that a malicious actor with network access can exploit to execute arbitrary code.
CVE-2026-47876 (CVSS 9.3 — Severity): An out-of-bounds write vulnerability in the VMXNET3 virtual network adapter of VMware ESX that a malicious actor with local administrative privileges on a virtual machine can exploit to execute code on the host.
CVE-2026-41703 (CVSS 7.6 — Severity): An out-of-bounds read vulnerability in VMware ESX that a malicious actor with VM deployment privileges could trigger, potentially leading to information disclosure or a denial-of-service condition.
CVE-2026-41709 (CVSS 2.7 — Severity): An insufficient logging vulnerability in VMware ESX that a malicious administrator can exploit to perform certain operations without them being logged. These vulnerabilities collectively present significant risks for organizations using VMware products, particularly those with high levels of network access and administrative privileges. Administrators should apply the latest security updates as soon as possible to mitigate these risks. These vulnerabilities collectively present significant risks for organizations using VMware products, particularly those with high levels of network access and administrative privileges.
These vulnerabilities collectively present significant risks for organizations using VMware products, particularly those with high levels of network access and administrative privileges.
We recommend you to update VMware Cloud Foundation and VMware vSphere Foundation to version 9.1.0.0300 or 9.0.2.0100, VMware vCenter version 8.0 Fixed in 8.0 U3k and VMware Cloud Foundation versions 5.x Async patch to 8.0 U3k.
The following reports contain further technical details:
[/emaillocker]