cognitive cybersecurity intelligence

News and Analysis

Search

Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System

Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System

Broadcom has released a critical security advisory, VMSA-2026-0006, addressing multiple high-impact vulnerabilities across core VMware virtualization platforms, including vCenter, ESX, Workstation, Fusion, Cloud Foundation, and several Telco Cloud offerings.

The flaws range from authentication bypass and directory traversal in vCenter to host-level code execution and insufficient logging issues in ESX, with CVSSv3 scores spanning 2.7 to 9.8.

The most severe issue, CVE-2026-59309, is an authentication-bypass vulnerability in the VMware Directory Service used by vCenter Server.

An attacker with network access to vCenter can exploit this flaw to fully bypass authentication and gain unauthorized access to the management plane, enabling complete control over virtual infrastructure, data, and connected workloads.

VMware Authentication Bypass

A second critical bug, CVE-2026-59310, is a directory traversal vulnerability in the vCenter Syslog server. By abusing path traversal, a remote attacker with network access can execute arbitrary code, turning vCenter into a beachhead for lateral movement and further compromise across the data center.

CVE-2026-47876 affects the VMXNET3 virtual network adapter in VMware ESX and is rated critical with a CVSSv3 score of 9.3.
A malicious actor with local administrative privileges inside a guest VM using VMXNET3 can trigger an out-of-bounds write, potentially executing code directly on the ESX host and escaping the virtual machine boundary.

Two additional ESX issues, CVE-2026-41703 and CVE-2026-41709, introduce important and low-severity risks, respectively.
CVE-2026-41703 is an out-of-bounds read in ESX, Workstation, and Fusion that can cause information disclosure or denial-of-service of the host process, while CVE-2026-41709 reflects insufficient logging on ESX, allowing administrators to perform certain operations without audit trails.

The advisory covers a broad range of VMware and Broadcom platforms used in enterprise, cloud, and telco environments.

CVE IDComponent / ProductVulnerability TypeCVSSv3 (Max)SeverityKey ImpactAttack Vector / RequirementsFix / Mitigation (High Level)CVE-2026-59309VMware vCenter (Directory Service)Authentication bypass9.8CriticalAllows attackers to bypass vCenter authentication and gain unauthorized access to the management plane.Network access to vCenter; no prior authentication required.Apply vCenter patches listed in the VMSA-2026-0006 response matrix (e.g., vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k).CVE-2026-59310VMware vCenter (Syslog server)Directory traversal → arbitrary code9.8CriticalEnables arbitrary code execution via path traversal, potentially leading to full vCenter compromise.Network access to vCenter; ability to reach Syslog service.Apply vCenter patches in response matrix for all affected versions; no workarounds available.CVE-2026-47876VMware ESX (VMXNET3 virtual network adapter)Out-of-bounds write → host code exec9.3CriticalAllows code execution on the ESX host from a compromised VM, enabling VM escape and host takeover.Local admin privileges inside a VM using VMXNET3 adapter.Patch ESX to fixed builds (ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, ESXi80U3k-25595708, and Cloud/Telco updates).CVE-2026-41703ESX, Workstation, FusionOut-of-bounds read7.6 / 2.7Important / LowCauses information disclosure and likely DoS of the host process; on Workstation/Fusion impact is limited to info disclosure.VM deployment privileges on ESX; local exploitation on Workstation/Fusion.Update ESX to fixed releases (ESXi-9.1.0.0-25370933, ESXi-9.0.2.0100-25595025, ESXi80U3i), and upgrade Workstation/Fusion from 25H2 to 26H1.CVE-2026-41709VMware ESXInsufficient logging2.7LowAllows certain administrative operations to be performed without being logged, reducing auditability.Malicious or rogue administrator on ESX.Patch ESX to fixed builds (ESXi-9.1.0.0-25370933, ESXi-9.0.2.0100-25595025, ESXi80U3j-25429389, Cloud Foundation 5.2.4, Telco KB449886).

Impacted products include VMware ESX, vCenter Server, Workstation, Fusion, VMware Cloud Foundation and vSphere Foundation, as well as VMware Telco Cloud Platform and Telco Cloud Infrastructure, significantly expanding the attack surface for organizations relying on VMware-based infrastructure.

Broadcom has released patches and updates across supported versions, with fixes for vCenter in Cloud Foundation and vSphere Foundation 9.1.x.x and 9.0.x.x, standalone vCenter 8.0 (8.0 U3k), and Cloud Foundation 5.x via async patches aligned to vCenter 8.0 U3k.

For ESX, fixes for VMXNET3 and logging/information disclosure issues are available in ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, ESXi80U3k-25595708, ESXi80U3i-25205845, and Cloud Foundation 5.x releases 5.2.3 and 5.2.4, alongside Telco-specific updates referenced in Broadcom KB449886.

Workstation and Fusion users are also affected by the out-of-bounds read vulnerability (CVE-2026-41703).
This issue is remediated by upgrading from version 25H2 to 26H1 on both platforms, reducing the risk of information disclosure from local exploitation.

Security teams should immediately prioritize patching vCenter instances exposed to internal or external networks, focusing on versions identified in the response matrix and ensuring upgrades to 9.1.0.0300, 9.0.2.0100, and 8.0 U3k where applicable.

ESX hosts using VMXNET3 network adapters should be patched without delay, and organizations should review logging policies and audit workflows after applying updates addressing CVE-2026-41709 to restore reliable visibility into administrative operations.
The post Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the System appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts