VMSA-2026-0006
July 31, 2026
·
0
Minutes Read

VMware Security Advisory

Advisory
Security Advisory
July 31, 2026
·
0
Minutes Read

VMware Security Advisory

Advisory
Security Advisory
July 31, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

On July 29, 2026, Broadcom released a critical VMware Security Advisory (VMSA-2026-0006) addressing multiple vulnerabilities in VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion. These vulnerabilities are critical and affect components within VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.

Affected Systems and/or Applications

The advisory affects the following VMware products:

  • VMware ESX
  • VMware vCenter
  • VMware Workstation
  • VMware Fusion
  • VMware Cloud Foundation
  • VMware vSphere Foundation
  • VMware Telco Cloud Platform
  • VMware Telco Cloud Infrastructure

Technical Details

The advisory details multiple vulnerabilities. The following vulnerabilities are the most critical:

  1. CVE-2026-59309: An authentication bypass in VMware vCenter's Directory Service, allowing unauthorized access. CVSSv3 score: 9.8.
  2. CVE-2026-59310: A directory traversal vulnerability in vCenter's Syslog server, enabling arbitrary code execution. CVSSv3 score: 9.8.
  3. CVE-2026-47876: An out-of-bounds write in the VMXNET3 virtual network adapter, allowing code execution on the ESX host from a virtual machine. CVSSv3 score: 9.3.

Mitigation

To mitigate these vulnerabilities, organizations should:

  • Apply the patches listed in the VMware Security Advisory for each affected product.
  • Ensure that all VMware products are updated to the latest versions as specified in the advisory.
  • Consider using ESX Live Patch and vCenter Quick Patch where applicable to reduce downtime during updates.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation. This advisory will be updated if required.

References

Related Post