Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Summary

Broadcom has released security updates for VMware products, addressing several vulnerabilities. Three of these flaws are rated as critical, including an authentication bypass in vCenter (CVE-2026-59309) with a CVSS score of 9.8, which could allow a malicious actor network access.

IFF Assessment

FOE

The discovery of critical vulnerabilities like authentication bypass and code execution in widely used virtualization software like VMware is bad news for defenders.

Severity

9.8 Critical

The CVSS score of 9.8 for CVE-2026-59309 indicates a critical severity, stemming from an authentication bypass vulnerability in VMware vCenter, which allows network access to potentially malicious actors.

Defender Context

Defenders should prioritize patching VMware products immediately to mitigate the risk of authentication bypass, code execution, and VM escape vulnerabilities. Staying informed about critical advisories for virtualization platforms is crucial for maintaining a secure infrastructure.

Read Full Story →