Our takeBroadcom patched CVE-2025-59309, a critical VM escape in ESXi plus auth bypass and RCE bugs in vCenter and the desktop products. Patch now if you run any of them.Cyber Resilience desk
Sources (2)
- securityweek · securityweek
- hackernews · hackernews
What this means for you — Security leader:Patch VMware ESXi, vCenter, Workstation, and Fusion for the five fixed flaws, including the critical vCenter auth bypass (CVE-2026-59309) and VM-escape issues. Prioritize internet-facing and management-network vCenter/ESXi hosts and verify the updates across clusters before returning them to production.
What this means for you — Lean IT orgs:Most lean-IT shops do not run VMware ESXi or vCenter themselves and can ignore this unless a hosting or IT provider does. If you depend on one, ask them whether their ESXi/vCenter stack is patched for these critical flaws.
What this means for you — MSP:Inventory every client estate running ESXi, vCenter, Workstation, or Fusion and schedule the Broadcom updates, starting with exposed vCenter and critical-severity hosts. Confirm patch completion per tenant and note any clusters that still need maintenance windows.
What this means for you — Researcher:Broadcom fixed five issues across ESXi, vCenter, Workstation, and Fusion; three are critical, including CVE-2026-59309 (vCenter auth bypass, CVSS 9.8) and VM-escape flaws. Compare advisory diffs and affected version ranges if you track hypervisor escape or vCenter attack surface.