# VMware fixes three critical flaws allowing auth bypass, VM escapes

_Thursday, July 30, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![VMware fixes three critical flaws allowing auth bypass, VM escapes — Primary](https://www.bleepstatic.com/content/hl-images/2023/10/25/VMware_red.jpg)

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. The three critical vulnerabilities are CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876. Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/)

---
Canonical: https://techandbusiness.org/newswire/zTqpoKsaZFLX-1is6pI00k
Retrieved: 2026-07-30T21:32:18.469Z
Publisher: Tech & Business (techandbusiness.org)
