Skip to main content

Broadcom Releases Security Update to Address Vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion

Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security advisory addresses vulnerabilities that could lead to arbitrary code execution, information disclosure, denial-of-service (DoS), authentication bypass, and unauthorised access


Threat details

Exploitation of CVE-2026-59310

Security researchers have observed exploitation of CVE-2026-59310. Observed successful exploitation attempts involved a threat actor using reverse SSH to maintain access to compromised vCenter systems.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Broadcom has released security updates to address vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion products.

  • CVE-2026-59309  - 'Authentication bypass' vulnerability -  CVSSv3 base score: 9.8.
  • CVE-2026-59310 - 'Directory traversal' vulnerability - CVSSv3 base score: 9.8.
  • CVE-2026-47876 - 'Out-of-bounds write' vulnerability - CVSSv3 base score: 9.8.
  • CVE-2026-41703 - 'Out-of-bounds read' vulnerability - CVSSv3 base score: 7.6. 

Threat updates

Date Update
12 Aug 2026 Escalated to High Severity

The following sections have been changed:

  • Exploitation details (warning box)
  • Remediation details and steps
  • CVE identifiers published and details added

Remediation advice

Affected organisations must review Broadcom's VMSA-2026-0006 advisory and apply the relevant updates as soon as possible.


Remediation steps

Type Step
Patch

Required: Update vCenter to a fixed version.

Affected organisations must update VMware vCenter to the latest fixed version available.

Note: vCenter is often bundled as a component of VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. These vCenter components must also be updated.


https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Patch

Strongly Recommended: Update all other vulnerable VMware products to the latest version.


https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017


Last edited: 12 August 2026 1:17 pm