VDB

CVE-2026-59309

CVE-2026-59309 PUBLISHED

On July 29, 2026, Broadcom released a critical VMware Security Advisory (VMSA), VMSA-2026-0006, addressing security vulnerabilities found and resolved in VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion. These components are part of the larger VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure software stacks. The advisory has since been updated to VMSA-2026-0006.2: version .1 added VMware vSphere 8.0 Update 2 patches, and version .2 added ESX and vCenter 7.0 patch guidance for customers with extended support. The VMSA will always be the source of truth for which products and versions are affected and the proper patches to keep your organization secure. This document is a supplement to the advisory and includes self-service information to help you and your organization decide how to respond. The advisory covers five issues: an authentication bypass in the VMware Directory Service, a directory traversal issue in the vCenter syslog server, an out-of-bounds write in the VMXNET3 virtual network adapter, an out-of-bounds read in ESX, Workstation, and Fusion, and an insufficient logging issue in ESX. The two vCenter issues permit an unauthenticated attacker with network access to bypass authentication and to execute arbitrary code. The VMXNET3 issue permits an attacker who already has administrative privileges inside a virtual machine to execute code on the ESX host. The out-of-bounds read requires

EPSS 0.61% · 47.3th percentile

Risk Scores

EPSS Score
0.61%
47.3th percentile

Timeline

  • Jul 28, 2026 CVE Published
  • Aug 7, 2026 EPSS Score
  • Aug 14, 2026 VulnCheck KEV Exploitation
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 21, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›