CRITICALApt
Global

Broadcom patches vulnerabilities all over VMware

·Source: CSO Online

Updated:

Executive Summary

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According t

Analysis

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication when accessing vCenter. The next vulnerability, CVE-2026-47876 , is an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter that could enable bad actors to execute code on the host. This does not affect non-VMXNET3 virtual adapters. CVE-2026-59310 affects VMware vCenter’s Syslog server that a malicious actor with network access could use to execute arbitrary code. The fourth issue, CVE-2026-41703 , is rated high, rather than critical, and concerns multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or a denial-of-service (DoS) condition in the host process. Last, and least critical, is CVE-2026-41709 : VMware ESX has insufficient logging capabilities, potentially enabling a malicious administrator to do things without being caught. Patches for all these vulnerabilities can be found in Broadcom’s VMSA-2026-0006 security advisory .

Indicators of Compromise (4)

CVE (4)
CVE-2026-47876
CVE-2026-59310
CVE-2026-41703
CVE-2026-41709
Source Attribution

Originally published by CSO Online on Jul 31, 2026.

Related Threats

MEDIUMApt

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as

The Hacker News
MEDIUMApt

Google adds to confusion with new names for threat actors

Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Anal

CSO Online
CRITICALApt

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

<p>CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modi

CISA Advisories