CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3456

As cited

Copy frozen at (site build).

vulnerabilities

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom released security updates for VMware ESX, vCenter, Workstation, and Fusion to address multiple flaws, including three rated critical. CVE-2026-59309, a critical authentication bypass in vCenter with a CVSS score of 9.8, allows network-accessible attackers to exploit the vulnerability.

Why it matters: Organizations running VMware vCenter, ESX, Workstation, or Fusion face immediate risk from authentication bypass and code execution vulnerabilities; patch deployment should be prioritized to prevent unauthorized access and lateral movement.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom released security updates for VMware ESX, vCenter, Workstation, and Fusion to address multiple flaws, including three rated critical. CVE-2026-59309, a critical authentication bypass in vCenter with a CVSS score of 9.8, allows network-accessible attackers to exploit the vulnerability.

Why it matters: Organizations running VMware vCenter, ESX, Workstation, or Fusion face immediate risk from authentication bypass and code execution vulnerabilities; patch deployment should be prioritized to prevent unauthorized access and lateral movement.

VendorsVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary