Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.
“A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system,” Broadcom said.
The second critical flaw is a directory-traversal vulnerability in vCenter (CVE-2026-59310, CVSS score: 9.8) that a malicious actor with network access can exploit to execute arbitrary code. Both vulnerabilities have been addressed in the versions below –
- VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
- VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
- VMware vCenter version 8.0 (Fixed in 8.0 U3k)
- VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)


Leave a Reply