VMSA-2026-0006: Urgent patch for VMware vCenter and ESX
Broadcom has released critical updates for vCenter, ESX, and other VMware products after discovering five vulnerabilities, two of which can be exploited without authentication.
Based on reporting by DNSC
Broadcom released security bulletin VMSA-2026-0006 on July 29, 2026, which fixes five vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. The DNSC issued a separate alert about this bulletin, recommending that the available patches be applied immediately.
What vulnerabilities have been discovered
The two most serious issues affect VMware vCenter Server and received the maximum severity score, 9.8 out of 10 on the CVSSv3 scale.
- CVE-2026-59309: An authentication bypass vulnerability in VMware Directory Service. An attacker with network access can bypass authentication and gain unauthorized access to the system.
- CVE-2026-59310: A directory traversal vulnerability in the Syslog Server component of vCenter that allows a remote attacker to execute arbitrary code, turning vCenter into a starting point for lateral network movement.
- CVE-2026-47876: Affects VMXNET3 virtual network adapter in ESX. It has a score of 9.3 and allows an attacker with local administrative privileges in a virtual machine to execute code directly on the host system, thus going outside the boundaries of the virtual machine.
- CVE-2026-41703: An out-of-bounds read in ESX, Workstation, and Fusion with a leak or service interruption impact.
- CVE-2026-41709: A low-severity ESXi insufficient logging issue with a score of 2.7.
Which products are affected
The bulletin covers VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, as well as the larger components that include: VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. All versions prior to those marked as fixed in the official bulletin are vulnerable.
Patched versions available
Broadcom has already released updates for all affected product lines.
- vCenter Server 8.0 is fixed with version 8.0 Update 3k.
- For vCenter 9.0, the patch is version 9.0.2.0100, and for line 9.1, version 9.1.0.0300.
- ESX 8.0 gets fix through ESXi80U3k-25595708, and for lines 9.0 and 9.1 there are dedicated updates.
- Cloud Foundation 5.x releases benefit from asynchronous fixing, separate from patches of individual components.
Broadcom specifies that patches are cumulative, so the latest version also includes previous fixes.
There are no workarounds
For the two critical vulnerabilities in vCenter there is no workaround. The only effective measure is to apply the updates published by Broadcom. At the moment, no active exploitation of these vulnerabilities has been reported in the real environment.
What System Administrators Need to Do
If you are administering VMware infrastructure, immediately check the installed version of vCenter and ESX and compare it to the repaired versions in VMSA-2026-0006. In addition to patching, consider additional protective measures.
- Restrict access to management interfaces through network segmentation and firewall rules.
- Enable multi-factor authentication for administrative accounts.
- Check your system logs for signs of unauthorized access or suspicious activity prior to patching.
If you manage virtualized infrastructure for customers or for your organization, treat this bulletin as an immediate priority, especially for vCenter servers exposed on the network.