HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Auth‑Bypass and VM‑Escape Flaws Fixed in VMware vCenter, ESX, Workstation (CVE‑2026‑59309, CVE‑2026‑59310, CVE‑2026‑47876)

Broadcom released patches for five VMware vulnerabilities, three of which are critical and enable authentication bypass, arbitrary code execution, or VM‑escape to the host. Organizations running vCenter, ESX, Workstation, Fusion, or related cloud‑foundation products must patch immediately; the incident underscores the need for continuous vulnerability‑management evidence in SOC 2 audits.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

VMware Releases Patches for Three Critical Auth‑Bypass and VM‑Escape Flaws Affecting vCenter, ESX, Workstation

What Happened — Broadcom disclosed five vulnerabilities in VMware vCenter, ESX, Workstation and Fusion, three of which are critical (CVE‑2026‑59309, CVE‑2026‑59310, CVE‑2026‑47876). The flaws allow unauthenticated attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the underlying host. Patches are now available for all affected product versions.

Why It Matters for Compliance & Audit Readiness

  • The authentication‑bypass and VM‑escape bugs illustrate a control gap that SOC 2 security and availability criteria require you to monitor continuously.
  • Demonstrating that you have a documented patch‑management process, with evidence of timely remediation, satisfies the “Change Management” and “Vulnerability Management” controls in the Trust Services Criteria.
  • Mapping these CVEs to your control inventory and retaining patch‑install logs creates audit‑ready evidence for both internal reviewers and external assessors.

Who Is Affected – Enterprises that run VMware vCenter, ESX, Workstation, Fusion, VMware Cloud Foundation, Telco Cloud Platform/Infrastructure, or any hosted workloads that rely on the VMXNET3 virtual NIC (e.g., cloud‑service providers, telecom operators, large‑scale data‑center operators).

Recommended Actions

  • Verify current product versions against the fixed releases (vCenter 9.1.0.0300, 9.0.2.0100, 8.0 Update 3k; ESXi 9.1.0.0200, 9.0.2.0100, 8.0 Update 3k; Workstation/Fusion 26H1).
  • Deploy the patches immediately on all affected systems; prioritize assets with external network exposure.
  • Record patch‑application dates, version numbers, and validation test results in your configuration‑management database (CMDB) for SOC 2 evidence.
  • Update your vulnerability‑management dashboard to flag any future releases for these products.

Technical Notes

  • CVE‑2026‑59309: Auth‑bypass in VMware Directory Service (CVSS 9.8).
  • CVE‑2026‑59310: Directory‑traversal leading to remote code execution via vCenter Syslog (CVSS 9.8).
  • CVE‑2026‑47876: Out‑of‑bounds write in VMXNET3 driver enabling VM‑escape to ESXi host (CVSS 9.3).
  • Additional lower‑severity issues: CVE‑2026‑41703 (out‑of‑bounds read) and CVE‑2026‑41709 (insufficient logging).

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →