Forwarding National Information Security Sharing and Analysis Center Cyber Security Alert NISAC-200-202608-00000001
Researchers have discovered 3 high-risk security vulnerabilities in multiple VMware products (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), categorized as Out-of-Bounds Write, Authentication Bypass, and Path Traversal, respectively. Please confirm and patch as soon as possible.
CVE-2026-47876: An attacker who has obtained local administrator privileges on the VMXNET3 network adapter of a virtual machine can execute arbitrary code on the ESXi host. CVE-2026-59309: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to bypass authentication without authorization and access the system.
CVE-2026-59310: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to execute arbitrary code.