CVE-2026-47876
On July 29, 2026, Broadcom released a critical VMware Security Advisory (VMSA), VMSA-2026-0006, addressing security vulnerabilities found and resolved in VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion. These components are part of the larger VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure software stacks. The VMSA will always be the source of truth for which products and versions are affected and the proper patches to keep your organization secure. This document is a supplement to the advisory and includes self-service information to help you and your organization decide how to respond. The advisory covers five issues: an authentication bypass in the VMware Directory Service, a directory traversal issue in the vCenter syslog server, an out-of-bounds write in the VMXNET3 virtual network adapter, an out-of-bounds read in ESX, Workstation, and Fusion, and an insufficient logging issue in ESX. The two vCenter issues permit an unauthenticated attacker with network access to bypass authentication and to execute arbitrary code. The VMXNET3 issue permits an attacker who already has administrative privileges inside a virtual machine to execute code on the ESX host. The out-of-bounds read requires virtual machine deployment privileges and can disclose information or cause a denial-of-service condition in the host process. The logging issue permits an administrator to perform operations on ESX with
Timeline
- Jul 29, 2026 CVE Published