48,91 ₺ 21:23
Cyber Security

VMware VMSA-2026-0006: vCenter Auth Bypass and ESXi VM Escape

2 min read 2 reads 3 questions answered

Why VMSA-2026-0006 is an emergency

On 29 July 2026 Broadcom published VMSA-2026-0006 covering five issues in VMware ESX, vCenter, Workstation and Fusion. The advisory was later updated to .2 (8.0 U2 express patches and 7.0 extended-support guidance). Overall severity is Critical; CVSSv3 ranges from 2.7 to 9.8. There are no official workarounds; Broadcom classifies the updates as an emergency change.

Affected products include vSphere ESXi, vCenter Server, VMware Cloud Foundation, vSphere Foundation, Telco Cloud and desktop hypervisors (Workstation / Fusion). If you run a private cloud or your own ESXi cluster in KuzeyDC colocation or dedicated space, this advisory belongs on your patch calendar immediately.

The three critical issues

  • CVE-2026-59309 (CVSS 9.8): authentication bypass in VMware Directory Service. An unauthenticated attacker with network access can bypass vCenter authentication.
  • CVE-2026-59310 (CVSS 9.8): directory traversal in the vCenter syslog server, with arbitrary code execution under the same access model.
  • CVE-2026-47876 (CVSS 9.3): out-of-bounds write in the ESXi VMXNET3 virtual NIC. An attacker with administrative rights inside a guest can execute code on the hypervisor (guest-to-host / VM escape).

Two additional issues: CVE-2026-41703 (Important, CVSS 7.6) out-of-bounds read on ESX / Workstation / Fusion; CVE-2026-41709 (Low) insufficient ESX logging so administrator actions may not be recorded.

What you should do

  1. Read the VMSA-2026-0006.2 patch matrix on the Broadcom portal; example vCenter targets include 9.1.0.0300, 9.0.2.0100 or 8.0 U3k / U2f express.
  2. Plan ESXi hosts (e.g. 8.0 U3k, 9.1.0.0200 line) with or before vCenter; the VMXNET3 escape is fixed on the hypervisor.
  3. Restrict vCenter to a management network: do not expose 443/5480/9443 to the internet; use a jump host or VPN.
  4. After patching, inventory vCenter/ESXi versions, VMs using VMXNET3 and the syslog service.

On KuzeyDC, hypervisor patching for VMware private cloud or colocation remains a customer responsibility; NOC can assist with physical access and remote hands. Schedule dedicated Linux guest kernel updates in the same window. Official source: Broadcom VMSA-2026-0006.

Frequently Asked Questions

Find answers to the most common questions about this topic below.

3 questions answered
Is there a workaround?

No. Broadcom published no workaround for any of the five CVEs; patching is the only durable fix. Restricting vCenter to a management network reduces exposure but does not close the bugs.

Is patching vCenter enough?

No. CVE-2026-47876 sits on ESXi VMXNET3; without a hypervisor patch the VM-escape risk remains.

Will KuzeyDC patch my hypervisor?

On customer-managed VMware in colocation, patching is yours. Plan remote hands and a maintenance window with NOC.

Back to Blog Contact