Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion.

Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter.

An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape.

The second critical flaw, CVE-2026-59309, is a vCenter authentication bypass that can be exploited to gain unauthorized access to the targeted system.

CVE-2026-59310 is also a critical vCenter vulnerability, allowing an attacker with network access to execute arbitrary code.