By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Broadcom Patches Three Critical VMware Security Flaws

Broadcom has issued critical security updates to address multiple vulnerabilities affecting VMware's virtualization products, including ESX, vCenter, Workstation, and Fusion. Three of these flaws have been classified as critical in severity, posing significant risks to users' systems. The first critical vulnerability, identified as CVE-2026-59309 with a CVSS score of 9.8, enables an authentication bypass in VMware vCenter. This flaw allows a malicious actor with network access to vCenter to circumvent authentication mechanisms, potentially gaining unauthorized access to sensitive information or control over the virtualized environment. The severity of this vulnerability underscores the importance of timely patching for vCenter Server, a central management component for VMware environments.
The second critical vulnerability, designated CVE-2026-59310 and also carrying a CVSS score of 9.8, is an authorization bypass flaw in VMware ESXi, ESXi for ARM, and Workstation. This vulnerability allows an attacker to bypass authorization controls, which could lead to unauthorized access or execution of privileged operations within the affected VMware products. The CVSS score of 9.8 indicates a high likelihood of exploitation and severe impact. VMware ESXi is a bare-metal hypervisor that forms the foundation of many enterprise data centers, making vulnerabilities within it particularly concerning.
The third critical vulnerability, CVE-2026-59311, with a CVSS score of 9.1, is a virtual machine escape flaw affecting VMware Workstation and VMware Fusion. A virtual machine escape allows an attacker to break out of the isolated environment of a virtual machine and gain access to the host operating system. This type of vulnerability is extremely dangerous as it can compromise the entire host system and any other virtual machines running on it. VMware Workstation and Fusion are desktop virtualization products used by developers and IT professionals for testing and running multiple operating systems on a single physical machine.
In addition to these three critical vulnerabilities, Broadcom has also addressed several other security issues with moderate and low severity ratings across the affected VMware products. The company strongly advises all users of VMware ESX, vCenter, Workstation, and Fusion to apply the provided security updates as soon as possible to mitigate the risks associated with these flaws. Failure to patch these vulnerabilities could leave organizations susceptible to data breaches, service disruptions, and unauthorized system access. The prompt release of these patches by Broadcom, following their acquisition of VMware, highlights the ongoing commitment to securing the virtualization infrastructure that underpins a vast portion of modern IT operations. The specific details of the vulnerabilities and the patches are available on Broadcom's security advisory portal.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.