# VMware ESX, vCenter, Workstation, and Fusion: Updates close critical gaps

_Thursday, July 30, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![VMware ESX, vCenter, Workstation, and Fusion: Updates close critical gaps — Primary](https://heise.cloudimg.io/bound/1200x1200/q85.png-lossy-85.webp-lossy-85.foil1/_www-heise-de_/imgs/18/5/1/3/0/4/9/5/VMware-Update-3-72f24f199aa04266.png)

Broadcom released security updates on Wednesday to close critical vulnerabilities in VMware ESX, vCenter, Workstation and Fusion, the company said in a security advisory.

Attackers can exploit a flaw in VMware Directory Service to bypass authentication and gain unauthorized access without a login, identified as CVE-2026-59309 with a CVSS score of 9.8. A path traversal vulnerability in the Syslog server allows arbitrary code injection and execution, tracked as CVE-2026-59310 with a CVSS score of 9.8. A memory boundary issue in the VMXNET3 virtual network adapter lets local administrators break out from a virtual machine to the host system, listed as CVE-2026-47876 with a CVSS score of 9.3.

Additional high-severity flaws include an out-of-bounds read vulnerability allowing information leakage or denial of service, and a logging gap that permits certain administrative operations to go unrecorded. Broadcom linked updated software packages for affected products, including VMware Cloud Foundation, vSphere Foundation, vCenter, ESXi, Fusion and Workstation.

## Sources

- [heise](https://www.heise.de/en/news/VMware-ESX-vCenter-Workstation-and-Fusion-Updates-close-critical-gaps-11387041.html)

---
Canonical: https://techandbusiness.org/newswire/jrpPiO0WF-DsMAzatGsgz7
Retrieved: 2026-07-31T18:08:57.610Z
Publisher: Tech & Business (techandbusiness.org)
