VMware patches in ESX, vCenter, Fusion, Cloud Foundation and more

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure
CVE-206-59309 affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication when accessing vCenter.
The next vulnerability, CVE-2026-47876, is an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter that could enable bad actors to execute code on the host. This does not affect non-VMXNET3 virtual adapters.