VMSA-2026-0006
July 31, 2026
·
0
Minutes Read
VMware Security Advisory
Advisory
Security Advisory
July 31, 2026
·
0
Minutes Read
VMware Security Advisory
Advisory
Security Advisory
July 31, 2026
·
0
Minutes Read
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Summary
On July 29, 2026, Broadcom released a critical VMware Security Advisory (VMSA-2026-0006) addressing multiple vulnerabilities in VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion. These vulnerabilities are critical and affect components within VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
Affected Systems and/or Applications
The advisory affects the following VMware products:
- VMware ESX
- VMware vCenter
- VMware Workstation
- VMware Fusion
- VMware Cloud Foundation
- VMware vSphere Foundation
- VMware Telco Cloud Platform
- VMware Telco Cloud Infrastructure
Technical Details
The advisory details multiple vulnerabilities. The following vulnerabilities are the most critical:
- CVE-2026-59309: An authentication bypass in VMware vCenter's Directory Service, allowing unauthorized access. CVSSv3 score: 9.8.
- CVE-2026-59310: A directory traversal vulnerability in vCenter's Syslog server, enabling arbitrary code execution. CVSSv3 score: 9.8.
- CVE-2026-47876: An out-of-bounds write in the VMXNET3 virtual network adapter, allowing code execution on the ESX host from a virtual machine. CVSSv3 score: 9.3.
Mitigation
To mitigate these vulnerabilities, organizations should:
- Apply the patches listed in the VMware Security Advisory for each affected product.
- Ensure that all VMware products are updated to the latest versions as specified in the advisory.
- Consider using ESX Live Patch and vCenter Quick Patch where applicable to reduce downtime during updates.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation. This advisory will be updated if required.
References
- VMware Security Advisory VMSA-2026-0006 on GitHub
- Broadcom Support Security Advisory
- CVE Details and Calculators
Related Post

.avif)


.webp)


.webp)