THREATOPS
THREAT OPSThreat News › Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

medthehackernewsPublished 2026-07-29

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.

The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.

"A malicious actor with network access to vCenter

Indicators of compromise

Original source: https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html

Same event, other sources