A flaw in vCenter is a control-plane problem, not a single-server problem. If an attacker reaches the management plane, they can try to take over the layer that governs ESXi hosts, virtual machines, and central administration.
Broadcom and national CERTs now give coordinated guidance for two critical vCenter issues: CVE-2026-59309, an authentication bypass, and CVE-2026-59310, a directory traversal flaw in the Syslog server that can lead to arbitrary code execution. Both affect unauthenticated attackers with network access, and there is still no known exploitation in the wild. Broadcom’s fixed versions are 8.0 U3k, 9.0.2.0100, and 9.1.0.0300, with related guidance also covering vSphere Foundation, Cloud Foundation, and Telco Cloud variants.
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
Broadcom ha rilasciato aggiornamenti di sicurezza per risolvere alcune nuove vulnerabilità, di cui 3 con gravità “critica” e una con gravità “alta”, in vari prodotti della suite VMware.