Overview
- Broadcom published a security advisory Wednesday, July 29, 2026, and released updates that remediate five vulnerabilities across VMware ESXi, vCenter, Workstation and Fusion.
- CVE-2026-47876 is an out‑of‑bounds write in the VMXNET3 virtual network adapter that a malicious user with local administrator rights inside a VM can use to run code on the ESXi host.
- CVE-2026-59309 is an authentication bypass in VMware vCenter and CVE-2026-59310 is a directory‑traversal flaw in vCenter’s Syslog server; both can be reached with network access and were rated Critical for their ability to grant unauthorized access or remote code execution.
- Broadcom also fixed CVE-2026-41703, a high‑severity info‑disclosure or denial‑of‑service issue, and CVE-2026-41709, an insufficient‑logging bug, and published fixed builds, version guidance and an FAQ to help administrators deploy patches.
- Broadcom says it has seen no evidence of active exploitation but warns that virtualization flaws are often targeted after advisories are released and urges immediate patching and validation to avoid host‑level or multi‑tenant compromise.