Caricamento…
  • July 31, 2026
  • Di aOneITForce

VMware Emergency Fixes Close Authentication Bypass and Virtual Machine Escape Paths

VMware Emergency Fixes Close Authentication Bypass and Virtual Machine Escape Paths

<p>Broadcom has released emergency security updates addressing a dangerous group of VMware vulnerabilities that reach across management servers, hypervisors and desktop virtualization products. Three of the five flaws are rated critical, and Broadcom says organizations running older builds should assume they are exposed.</p><p>Two vulnerabilities affect vCenter, the management layer used to administer virtualized infrastructure. CVE-2026-59309 is an authentication bypass in VMware Directory Service. An attacker with network access to vCenter could potentially enter the system without valid credentials. CVE-2026-59310 is a directory traversal problem in the vCenter Syslog server that can lead to arbitrary code execution without authentication.</p><h2>A route from a guest VM to the host</h2><p>The third critical issue, CVE-2026-47876, affects the VMXNET3 virtual network adapter. An attacker who already has administrative control inside a virtual machine could exploit an out-of-bounds write to execute code on the ESX host. This creates a virtual machine escape scenario, breaking one of the most important isolation boundaries in a virtualized data center.</p><p>Two additional vulnerabilities involve an out-of-bounds read and insufficient administrative logging. Although they carry lower severity ratings, they could still assist an attacker by exposing information, disrupting host processes or hiding certain actions from routine audit records.</p><p>The impact extends beyond individual vCenter and ESX installations. Products incorporating those components, including VMware Cloud Foundation, VMware vSphere Foundation and several telecommunications platforms, also require attention. VMware Workstation and Fusion customers using version 25H2 must move to 26H1 to address the relevant desktop vulnerability.</p><h2>No workaround changes the urgency</h2><p>Broadcom has not provided a workaround for the flaws. It also advises against switching virtual machines away from VMXNET3 as an improvised mitigation because alternative adapters may introduce performance problems and have had security issues of their own.</p><h3>Recommended response</h3><ul><li>Inventory every vCenter, ESX, Workstation, Fusion and Cloud Foundation deployment.</li><li>Restrict management interfaces to dedicated administrative networks.</li><li>Install the fixed versions using an emergency change process.</li><li>Review vCenter authentication activity and administrative account changes.</li><li>Investigate unusual communication between guest systems and hypervisor services.</li></ul><p>I believe virtualization teams should treat these updates as infrastructure-level incident prevention, not ordinary monthly maintenance. A compromised vCenter server can expose a large portion of an organization's computing environment, while a successful VM escape can undermine assumptions about workload separation. The safest response is rapid patching followed by a focused review for evidence of unauthorized management activity.</p>

Torna su