Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.
The five vulnerabilities are summarized below:
CVE-2026-59309: A critical authentication bypass vulnerability in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system.












