Security Affairs
ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog|Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected|MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data|DentaQuest disclosed a data breach that impacted +23 million individuals|ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog|Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected|MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data|DentaQuest disclosed a data breach that impacted +23 million individuals|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a […]

VMware ESXi Fusion Pwn2Own Berlin 2025

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine.

Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a VM escape flaw in the VMXNET3 virtual network adapter. An attacker with administrator privileges inside a virtual machine could exploit it to execute arbitrary code on the underlying ESXi host.

“VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.” reads the advisory. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.”

Broadcom also fixed a critical vCenter authentication bypass, tracked as CVE-2026-59309 (CVSSv3 base score of 9.8), that can be exploited to gain unauthorized access to the targeted system.

“VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory. “A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.”

The third critical issue fixed by the company is CVE-2026-59310 (CVSSv3 base score of 9.8), a flaw allowing an attacker with network access to execute arbitrary code. 

“VMware vCenter contains a directory traversal vulnerability in the Syslog server. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.”states the advisory.”A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.”

The vendor also patched CVE-2026-41703 (CVSSv3 score of 7.6), a high-severity flaw affecting VMware ESXi, Workstation, and Fusion that could allow an attacker with VM deployment permissions to disclose information or cause a denial-of-service on the host. Another issue, CVE-2026-41709 (CVSSv3 score of 7.6), lets an administrator perform certain actions on ESXi without logging in. Although no active exploitation has been reported, Broadcom urges customers to apply the updates promptly.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, virtual machine)