Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

Broadcom informs VMware product users that patches are available for vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion.

Broadcom fixes two critical VMware vCenter flaws and a VMXNET3 ESX escape, with no evidence of exploitation in the wild.