Affected Systems
VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Critical vulnerabilities affect vCenter authentication (CVE-2026-59309, CVSS 9.8), vCenter Syslog (CVE-2026-59310, CVSS 9.8), and VMXNET3 adapter in ESXi (CVE-2026-47876, CVSS 9.3).
Exploitation Status
No active exploitation observed by Broadcom as of advisory publication. No public PoC available yet. However, VMware infrastructure is a high-value target historically exploited by ransomware groups and nation-state actors (e.g., Chinese threat actors deploying BrickStorm malware in December 2025).
Business Impact
Critical risk to virtualization infrastructure. CVE-2026-59309 allows unauthenticated network attackers to bypass vCenter authentication and gain full system access. CVE-2026-59310 enables unauthenticated remote code execution via vCenter Syslog. CVE-2026-47876 permits VM escape to ESXi host for attackers with local admin in VMs using VMXNET3 adapter. Successful exploitation grants access to entire virtual infrastructure, hosted workloads, and sensitive data. ESXi patching requires host reboots; vCenter updates interrupt management interfaces temporarily. VMware Cloud Foundation 9.x upgrades blocked until future compatibility fix.
Urgency
🔴 Immediate
Recommended Actions
- Immediately patch vCenter Server to version 9.1.0.0300, 9.0.2.0100, or 8.0 Update 3k depending on branch. Expect temporary interruption to vSphere Client and management interfaces during update.
- Patch ESXi hosts to version 9.1.0.0200, 9.0.2.0100, or 8.0 Update 3k. Use vMotion for rolling reboots across clusters to minimize downtime. Apply ESXi Live Patch where supported to reduce disruption.
- Upgrade VMware Workstation and Fusion from 25H2 to 26H1 to address CVE-2026-41703.
- Monitor vCenter and ESXi access logs for anomalous authentication attempts, unexpected administrative actions, or unauthorized VM deployments. Review for signs of BrickStorm malware or VirtualGHOST persistence techniques.
- Restrict network access to vCenter Server and ESXi management interfaces to trusted admin networks only. Implement network segmentation and firewall rules to limit exposure of CVSS 9.8 unauthenticated attack vectors.
