VMware security advisory VMSA-2026-0006

vmware-security-advisory-vmsa-2026-0006-01

Broadcom published VMware security advisory VMSA-2026-0006 addressing multiple vulnerabilities across several VMware products.

The reported vulnerabilities impact the following platforms:

  • VMware ESXi, vCenter Server, Workstation, and Fusion
  • VMware Cloud Foundation and vSphere Foundation
  • Telco Cloud Platform and Telco Cloud Infrastructure

VMSA-2026-0006 1

Most notably, there are two critical vulnerabilities affecting vCenter Server, both carrying a CVSSv3.1 score of 9.8:

  • CVE-2026-59309 - Allows a malicious actor with network access to bypass authentication and gain unauthorized access to the system.
  • CVE-2026-59310 - Allows a malicious actor with network access to execute arbitrary code.

Broadcom has already released patches to mitigate these issues. Organizations using vCenter Server should apply these updates as soon as possible to prevent potential exploitation.

VMSA-2026-0006 2

 

Remediation and mitigation of VMSA-2026-0006

Alongside the vCenter patches, Broadcom addressed three additional vulnerabilities:

  • CVE-2026-47876 (score CVSS: 9.3) - An out-of-bounds write flaw in the VMXNET3 virtual network adapter allows a malicious actor with local admin privileges on a VM to execute arbitrary code on the underlying host.

VMSA-2026-0006 3

  • CVE-2026-41703 (score CVSS: 7.6) - An out-of-bounds read vulnerability triggered during VM deployment. On ESXi, it can lead to information disclosure or a Denial-of-Service (DoS) condition. On Workstation and Fusion, the impact is strictly limited to information disclosure.

VMSA-2026-0006 4

  • CVE-2026-41709 (score CVSS: 2.7) - An insufficient logging flaw allows a malicious administrator to perform specific unauthorized operations without generating log entries.

VMSA-2026-0006 5

Because these are critical security patches, it is strongly recommended to apply them as soon as possible to mitigate potential risks.

signature

Leave a Reply