VMware ESXi and Other Products Hit by Critical VM Escape and Authentication Bypass Vulnerabilities
VMware has released patches for five vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion, including a critical VM escape flaw in ESXi's VMXNET3 virtual network adapter.

Broadcom has issued a critical security advisory detailing five vulnerabilities affecting multiple VMware products, including ESXi, vCenter, Workstation, and Fusion. Three of these flaws have been assigned a 'critical' severity rating, with one particularly concerning vulnerability allowing for a VM escape.
The critical VM escape vulnerability, identified as CVE-2026-47876, resides in VMware's VMXNET3 virtual network adapter within ESXi. An attacker who gains local administrative privileges on a virtual machine equipped with this adapter can exploit this flaw to execute arbitrary code on the host system, effectively breaking out of the virtualized environment and compromising the underlying infrastructure.
Adding to the severity, another critical vulnerability, CVE-2026-59309, affects vCenter Server and enables an authentication bypass. This could allow an attacker to gain unauthorized access to targeted vCenter systems without proper credentials. Furthermore, CVE-2026-59310, also a critical flaw in vCenter, permits an attacker with network access to execute arbitrary code on the affected server.
Beyond these critical issues, VMware ESXi, Workstation, and Fusion are impacted by CVE-2026-41703, a high-severity vulnerability. This flaw could lead to a denial-of-service (DoS) condition on the host process or allow an attacker with VM deployment permissions to obtain sensitive information.
A fifth vulnerability, CVE-2026-41709, is a low-severity issue affecting ESXi. It allows an attacker with administrative privileges to perform certain actions on the system without being logged in, potentially aiding in reconnaissance or further exploitation.
While Broadcom has stated it is not aware of any in-the-wild exploitation of these specific vulnerabilities, the company strongly urges organizations to update their VMware products to the latest patched versions. Threat actors frequently target VMware environments due to their widespread use in enterprise data centers and cloud infrastructures.
In response to the disclosure, VMware has published a comprehensive FAQ to guide users on the impact of these vulnerabilities and the necessary patching procedures. Prompt application of these updates is crucial to protect against potential compromise and maintain the security posture of virtualized environments.
This new advisory from Broadcom, VMSA-2026-0006, details additional critical vulnerabilities beyond those initially reported, including CVE-2026-59309 and CVE-2026-59310 in vCenter, which allow for authentication bypass and arbitrary code execution, respectively. It also highlights CVE-2026-47876, a VM escape vulnerability in ESX's VMXNET3 virtual network adapter, and expands the scope to include VMware Cloud Foundation and Telco Cloud offerings.