VDB

CVE-2026-59309

CVE-2026-59309 PUBLISHED

On July 29, 2026, Broadcom released a critical VMware Security Advisory (VMSA), VMSA-2026-0006, addressing security vulnerabilities found and resolved in VMware ESX, VMware vCenter, VMware Workstation, and VMware Fusion. These components are part of the larger VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure software stacks. The advisory has since been updated to VMSA-2026-0006.1 with the addition of VMware vSphere 8.0 Update 2 patches. The VMSA will always be the source of truth for which products and versions are affected and the proper patches to keep your organization secure. This document is a supplement to the advisory and includes self-service information to help you and your organization decide how to respond. The advisory covers five issues: an authentication bypass in the VMware Directory Service, a directory traversal issue in the vCenter syslog server, an out-of-bounds write in the VMXNET3 virtual network adapter, an out-of-bounds read in ESX, Workstation, and Fusion, and an insufficient logging issue in ESX. The two vCenter issues permit an unauthenticated attacker with network access to bypass authentication and to execute arbitrary code. The VMXNET3 issue permits an attacker who already has administrative privileges inside a virtual machine to execute code on the ESX host. The out-of-bounds read requires virtual machine deployment privileges and can disclose information or cause a denial-of-s

EPSS 0.74% · 51.3th percentile

Risk Scores

EPSS Score
0.74%
51.3th percentile

Timeline

  • Jul 29, 2026 CVE Published
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›