Cyber Resilience
← All news
Corroborated

Critical VM Escape Vulnerability Patched in VMware ESXi

Our takeBroadcom patched CVE-2025-59309, a critical VM escape in ESXi plus auth bypass and RCE bugs in vCenter and the desktop products. Patch now if you run any of them.
Sources (2)
What this means for you — Security leader:Patch VMware ESXi, vCenter, Workstation, and Fusion for the five fixed flaws, including the critical vCenter auth bypass (CVE-2026-59309) and VM-escape issues. Prioritize internet-facing and management-network vCenter/ESXi hosts and verify the updates across clusters before returning them to production.
What this means for you — Lean IT orgs:Most lean-IT shops do not run VMware ESXi or vCenter themselves and can ignore this unless a hosting or IT provider does. If you depend on one, ask them whether their ESXi/vCenter stack is patched for these critical flaws.
What this means for you — MSP:Inventory every client estate running ESXi, vCenter, Workstation, or Fusion and schedule the Broadcom updates, starting with exposed vCenter and critical-severity hosts. Confirm patch completion per tenant and note any clusters that still need maintenance windows.
What this means for you — Researcher:Broadcom fixed five issues across ESXi, vCenter, Workstation, and Fusion; three are critical, including CVE-2026-59309 (vCenter auth bypass, CVSS 9.8) and VM-escape flaws. Compare advisory diffs and affected version ranges if you track hypervisor escape or vCenter attack surface.