VMSA-2026-0006: Up to 3 VMware vulnerabilities are rated as "Critical"
- Kamy Le
- 3 hours ago
- 4 min read
Broadcom has officially released VMware Security Advisory (VMSA-2026-0006) to urgently address 5 vulnerabilities across several of its software product lines. Notably, up to 3 vulnerabilities are rated as "Critical", posing risks that could allow attackers to launch unauthenticated attacks or even escape virtual machines to attack the underlying physical hosts.

The duo of "CVSS 9.8" vulnerabilities in vCenter and threats from internal networks
Among the newly disclosed flaws, two vulnerabilities targeting the VMware vCenter centralized management platform are rated near-maximum severity on the Common Vulnerability Scoring System (CVSS) scale (9.8/10). Both vulnerabilities allow an attacker with network access to the system to exploit them without needing any authentication or valid credentials:
Authentication bypass flaw (CVE-2026-59309): The vulnerability exists in the VMware Directory Service. Malicious actors can exploit this weakness to bypass identity checks and immediately gain unauthorized access to the entire vCenter management system.
Remote code execution flaw (CVE-2026-59310): This is a directory-traversal vulnerability located in the vCenter logging server (syslog). The flaw allows attackers to freely execute arbitrary commands or malicious code on the target system.

Alarm over "VM Escapes" and other system risks
Alongside the two 9.8-score vulnerabilities in vCenter, Broadcom's patch cycle also addresses three other vulnerabilities, including a critical bug on the ESX host platform and two moderate- and low-impact flaws:
Virtual machine escape risk (CVE-2026-47876 - CVSS 9.3): This is an out-of-bounds memory write/buffer overflow flaw located in VMXNET3 - VMware ESX's virtualized network adapter. Broadcom classifies this bug as a "virtual machine escape" scenario. Specifically, if an attacker has gained local administrative privileges inside a virtual machine using the VMXNET3 adapter, they can break out of the virtual machine's isolation boundary to execute malicious code directly on the physical ESX host system.
Risk of data disclosure and service disruption (CVE-2026-41703 - CVSS 7.6): An out-of-bounds memory read flaw on ESX can be triggered by an entity with privileges to deploy virtual machines, leading to information leakage or host process crashes (causing a Denial of Service - DoS condition). For users of Workstation and Fusion software, the impact of this flaw is limited to information disclosure.
Anonymous administrative operations (CVE-2026-41709 - CVSS 2.7): A vulnerability caused by incomplete logging mechanisms on ESX. The risk from this flaw lies in the ability of a malicious administrator to perform certain actions on ESX without the system logging any traces in the activity log.
Broadcom stated that to date, the company has observed no evidence indicating that these vulnerabilities have been exploited in real-world attacks.
Widespread scope of impact across the entire VMware ecosystem
This is a crucial section that IT managers and security teams need to pay special attention to, as the scope of this patch cycle extends beyond standalone software to encompass integrated cloud infrastructure platforms.
First, the 4 directly affected core product lines include:
VMware ESX
VMware vCenter
VMware Workstation
VMware Fusion
However, the risk does not stop at standalone installations. The VMSA advisory emphasizes an important rule: Any system, software suite, or integrated product containing ESX or vCenter components inside is automatically affected. Therefore, Broadcom's large-scale cloud solutions and infrastructure platforms listed below are also fully exposed and require remediation:
VMware Cloud Foundation: Releases in the 5.x branch, 9.0.x.x branch, and 9.1.x.x branch are all affected.
VMware vSphere Foundation: Including versions in the 9.0.x.x and 9.1.x.x branches.
VMware Telco Cloud Platform: Specialized cloud platform for the telecommunications industry.
VMware Telco Cloud Infrastructure: Cloud infrastructure for telecom operators.
Broadcom explicitly advises that if your organization is running any version of the product lines mentioned above that is lower than the officially published "fixed" version in the VMSA advisory, that system is undoubtedly affected. If technical teams have any doubt or confusion about whether their systems are vulnerable, the vendor advises always defaulting to assuming the system is vulnerable to immediately deploy protective measures.
Detailed action recommendations for enterprises and IT teams
Based on Information Technology Infrastructure Library (ITIL) standards, Broadcom confirms that all of these vulnerabilities are classified under the emergency change category. This means organizations need to respond urgently without delay. To ensure infrastructure system safety, organizations should implement the following specific steps:
Immediately consult with the information security department: IT engineers and managers need to consult immediately with the organization's cybersecurity team to jointly assess the actual context of the system, thereby deciding on the most suitable schedule and handling plan for their unit.
Update patches on vCenter:
For VMware vCenter version 8.0: Upgrade immediately to version 8.0 U3k.
For VMware Cloud Foundation version 5.x: Update the asynchronous patch (Async patch) to 8.0 U3k.
For VMware Cloud Foundation and vSphere Foundation version 9.0.x.x: Upgrade to fixed version 9.0.2.0100.
For VMware Cloud Foundation and vSphere Foundation version 9.1.x.x: Upgrade to fixed version 9.1.0.0300.
Update patches for ESX, Workstation, and Fusion:
Remediate the "VM escape" vulnerability on ESX: Install patch ESXi80U3k-25595708, or update the Cloud Foundation/vSphere Foundation suite to fixed versions ESXi-9.0.2.0100-25595025 and ESXi-9.1.0.0200-25557999.
Remediate out-of-bounds flaws on personal computers: Individual users and engineers using virtual machines on desktop computers should immediately upgrade VMware Workstation to version 26H1 and VMware Fusion to version 26H1.
Apply the principle of cumulative patches: The list of updates provided by Broadcom is cumulative in nature. This means that any software version newer than those listed above already includes fixes for these vulnerabilities.
Cross-check with VMSA documentation: The IT department must always regard the original VMware Security Advisory (VMSA) as the "single source of truth" to accurately cross-reference version build numbers and patch download paths for each specific cluster.
Although attackers have not yet exploited these vulnerabilities in the wild, with severity scores reaching up to 9.8 and risks ranging from internal network attacks to virtual machine escapes, patching is an urgent task that cannot be delayed for any organization operating VMware infrastructure.
Reference: The Hacker News






