Skip to main content

Broadcom Releases Security Update to Address Vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion

Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access


Threat details

Introduction

Broadcom has released security updates to address vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion products.

  • CVE-2026-59309  - 'Authentication bypass' vulnerability -  CVSSv3 base score: 9.8.
  • CVE-2026-59310 - 'Directory traversal' vulnerability - CVSSv3 base score: 9.8.
  • CVE-2026-47876 - 'Out-of-bounds write' vulnerability - CVSSv3 base score: 9.8.
  • CVE-2026-41703 - 'Out-of-bounds read' vulnerability - CVSSv3 base score: 7.6. 

Remediation advice

Affected organisations are encouraged to review Broadcom's VMSA-2026-0006 advisory and apply the relevant updates as soon as possible.



Last edited: 29 July 2026 2:28 pm