Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom patches three critical VMware flaws — including VM escape and auth bypass in vCenter/ESXi — giving attackers a path from guest to host in unpatched environments.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readRead at source ↗

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

Editorial Analysis

Why it matters

Hypervisor-layer vulnerabilities carry outsized blast radius; a single exploited ESXi host can expose every guest VM and the data they hold.

What to do

Apply Broadcom's patches on an emergency schedule, prioritising internet-facing vCenter instances and production ESXi hosts.

Board brief

Three critical VMware vulnerabilities allow attackers to escape virtual machines and bypass authentication — emergency patching is required.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the Vulnerabilities Desk