Why VMSA-2026-0006 is an emergency
On 29 July 2026 Broadcom published VMSA-2026-0006 covering five issues in VMware ESX, vCenter, Workstation and Fusion. The advisory was later updated to .2 (8.0 U2 express patches and 7.0 extended-support guidance). Overall severity is Critical; CVSSv3 ranges from 2.7 to 9.8. There are no official workarounds; Broadcom classifies the updates as an emergency change.
Affected products include vSphere ESXi, vCenter Server, VMware Cloud Foundation, vSphere Foundation, Telco Cloud and desktop hypervisors (Workstation / Fusion). If you run a private cloud or your own ESXi cluster in KuzeyDC colocation or dedicated space, this advisory belongs on your patch calendar immediately.
The three critical issues
- CVE-2026-59309 (CVSS 9.8): authentication bypass in VMware Directory Service. An unauthenticated attacker with network access can bypass vCenter authentication.
- CVE-2026-59310 (CVSS 9.8): directory traversal in the vCenter syslog server, with arbitrary code execution under the same access model.
- CVE-2026-47876 (CVSS 9.3): out-of-bounds write in the ESXi VMXNET3 virtual NIC. An attacker with administrative rights inside a guest can execute code on the hypervisor (guest-to-host / VM escape).
Two additional issues: CVE-2026-41703 (Important, CVSS 7.6) out-of-bounds read on ESX / Workstation / Fusion; CVE-2026-41709 (Low) insufficient ESX logging so administrator actions may not be recorded.
What you should do
- Read the VMSA-2026-0006.2 patch matrix on the Broadcom portal; example vCenter targets include 9.1.0.0300, 9.0.2.0100 or 8.0 U3k / U2f express.
- Plan ESXi hosts (e.g. 8.0 U3k, 9.1.0.0200 line) with or before vCenter; the VMXNET3 escape is fixed on the hypervisor.
- Restrict vCenter to a management network: do not expose 443/5480/9443 to the internet; use a jump host or VPN.
- After patching, inventory vCenter/ESXi versions, VMs using VMXNET3 and the syslog service.
On KuzeyDC, hypervisor patching for VMware private cloud or colocation remains a customer responsibility; NOC can assist with physical access and remote hands. Schedule dedicated Linux guest kernel updates in the same window. Official source: Broadcom VMSA-2026-0006.