{"id":16540,"date":"2026-07-31T13:42:59","date_gmt":"2026-07-31T13:42:59","guid":{"rendered":"https:\/\/newestek.com\/?p=16540"},"modified":"2026-07-31T13:42:59","modified_gmt":"2026-07-31T13:42:59","slug":"broadcom-patches-vulnerabilities-all-over-vmware","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16540","title":{"rendered":"Broadcom patches vulnerabilities all over VMware"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a \u201ccritical\u201d rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-59309\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-206-59309<\/a> affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication when accessing vCenter.<\/p>\n<p class=\"wp-block-paragraph\">The next vulnerability, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-47876\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-47876<\/a>, is an out-of-bounds write issue in ESXi\u2019s VMXNET3 virtual network adapter that could enable bad actors to execute code on the host. This does not affect non-VMXNET3 virtual adapters.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-59310\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-59310<\/a> affects VMware vCenter\u2019s Syslog server that a malicious actor with network access could use to execute arbitrary code.<\/p>\n<p class=\"wp-block-paragraph\">The fourth issue, <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-41703\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-41703<\/a>, is rated high, rather than critical, and concerns multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or a denial-of-service (DoS) condition in the host process.<\/p>\n<p class=\"wp-block-paragraph\">Last, and least critical, is <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-41709\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-41709<\/a>: VMware ESX has insufficient logging capabilities, potentially enabling a malicious administrator to do things without being caught.<\/p>\n<p class=\"wp-block-paragraph\">Patches for all these vulnerabilities can be found in <a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/38017\" target=\"_blank\" rel=\"noreferrer noopener\">Broadcom\u2019s VMSA-2026-0006 security advisory<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a \u201ccritical\u201d rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom, this vulnerability could enable a malicious hacker to bypass authentication&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16540\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16540","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16540","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16540"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16540\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}