Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates SecurityWeek

Critical VM Escape Vulnerability Patched in VMware ESXi

Broadcom has patched five vulnerabilities in VMware products, including three rated critical. The most severe is CVE-2026-47876, a VM escape flaw in the ESXi VMXNET3 adapter where an attacker with local admin privileges on a guest VM can execute arbitrary code on the host. The other critical flaws are an authentication bypass (CVE-2026-59309) and a remote code execution vulnerability (CVE-2026-59310) in vCenter. Organizations should apply the vendor-provided updates immediately, as detailed in the published security advisory and FAQ.
Read Full Article →

Vulnerabilities Critical VM Escape Vulnerability Patched in VMware ESXi A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. By Eduard Kovacs | July 29, 2026 (7:42 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion. Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape. The second critical flaw, CVE-2026-59309, is a vCenter authentication bypass that can be exploited to gain unauthorized access to the targeted system. CVE-2026-59310 is also a critical vCenter vulnerability, allowing an attacker with network access to execute arbitrary code. VMware ESXi, Workstation, and Fusion are affected by CVE-2026-41703, a high-severity vulnerability that allows an attacker with VM deployment permissions to obtain information or, more likely, cause a DoS condition on the host process. Advertisement. Scroll to continue reading. The last flaw, CVE-2026-41709, is a low-severity issue in ESXi that allows an attacker with admin privileges to conduct certain activities without being logged. Broadcom is not aware of the in-the-wild exploitation of these vulnerabilities, but it’s important that organizations install the latest updates, as threat actors often exploit flaws in VMware products. In addition to its advisory , the vendor has published an FAQ detailing the impact of the vulnerabilities and patching requirements. Related : 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Related : High-Severity Vulnerability Patched in VMware Fusion Related : VMware Aria Operations Vulnerability Exploited in the Wild Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Origin Energy Data Breach Affects 900,000 Australians Nvidia and Tech Giants Launch AI Security Alliance Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits MCBS Data Breach Affects 1.2 Million Individuals Rockwell Patches Code Execution Flaws in Arena Simulation Software Data Breach Confirmed After Australian Energy Giant Origin Is Hacked Latest News US, Australia Release OT Isolation Guidance for Critical Infrastructure OpenAI’s Rogue AI Ventured Beyond Hugging Face Spur Raises $200 Million for IP Intelligence Platform JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks ShinyHunters Claims Ernst & Young Hack Cyera Acquiring Oasis Security in $1 Billion Deal Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer. John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox. Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer. More People On The Move Expert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Share this article