CRITICALApt
Global
Broadcom patches vulnerabilities all over VMware
·Source: CSO Online
Updated:
Executive Summary
Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According t
Analysis
Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication when accessing vCenter. The next vulnerability, CVE-2026-47876 , is an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter that could enable bad actors to execute code on the host. This does not affect non-VMXNET3 virtual adapters. CVE-2026-59310 affects VMware vCenter’s Syslog server that a malicious actor with network access could use to execute arbitrary code. The fourth issue, CVE-2026-41703 , is rated high, rather than critical, and concerns multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or a denial-of-service (DoS) condition in the host process. Last, and least critical, is CVE-2026-41709 : VMware ESX has insufficient logging capabilities, potentially enabling a malicious administrator to do things without being caught. Patches for all these vulnerabilities can be found in Broadcom’s VMSA-2026-0006 security advisory .