A single VMware patch does not clear the whole risk surface here. These flaws split across the management plane, the host, and desktop hypervisors, so fixing vCenter alone does not protect an ESXi host or a VM that can already run as admin.
INCIBE’s consolidated advisory covers five VMware issues across ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products. The critical ones include a vCenter authentication bypass, a vCenter syslog traversal flaw that can lead to code execution, and CVE-2026-47876 in VMXNET3, where a local VM admin can break out to the host. The other two affect ESX, Workstation, and Fusion with out-of-bounds reads or weak logging, which broadens the blast radius beyond one control plane.
The practical reading is that guest compromise, host compromise, and management-plane compromise are all on the table in the same advisory. Patching needs to match the layer under attack, or one fixed component can leave another still open.