#3
The Hacker News
general
July 29, 2026 at 15:31 UTC
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
By [email protected] (The Hacker News)
AI Summary
Broadcom patched five vulnerabilities across VMware ESXi, vCenter, Workstation, and Fusion, including CVE-2026-59309 (CVSS 9.8), an authentication bypass in vCenter that allows a network-adjacent attacker to gain unauthorized access without credentials. Additional critical flaws enable code execution and VM escape, making this a high-priority patch cycle for any organization running VMware virtualization infrastructure. These product lines are perennial targets for ransomware operators and nation-state actors.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →