Home / Jul 30, 2026 / Story
0
#3 The Hacker News general July 29, 2026 at 15:31 UTC

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

By [email protected] (The Hacker News)

AI Summary

Broadcom patched five vulnerabilities across VMware ESXi, vCenter, Workstation, and Fusion, including CVE-2026-59309 (CVSS 9.8), an authentication bypass in vCenter that allows a network-adjacent attacker to gain unauthorized access without credentials. Additional critical flaws enable code execution and VM escape, making this a high-priority patch cycle for any organization running VMware virtualization infrastructure. These product lines are perennial targets for ransomware operators and nation-state actors.

Relevance score: 86.0/100

# More from July 30