Broadcom Releases Security Update to Address Vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion
Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access
Summary
Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Broadcom has released security updates to address vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion products.
- CVE-2026-59309 - 'Authentication bypass' vulnerability - CVSSv3 base score: 9.8.
- CVE-2026-59310 - 'Directory traversal' vulnerability - CVSSv3 base score: 9.8.
- CVE-2026-47876 - 'Out-of-bounds write' vulnerability - CVSSv3 base score: 9.8.
- CVE-2026-41703 - 'Out-of-bounds read' vulnerability - CVSSv3 base score: 7.6.
Remediation advice
Affected organisations are encouraged to review Broadcom's VMSA-2026-0006 advisory and apply the relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 29 July 2026 2:28 pm