Posting Date: 2026/08/03
【Vulnerability Alert】VMware multiple products contain 3 high-risk security vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), please confirm and patch as soon as possible
- Subject: 【Vulnerability Alert】VMware multiple products contain 3 high-risk security vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), please confirm and patch as soon as possible
- Description:
- Forwarding National Information Security Sharing and Analysis Center Cyber Security Alert NISAC-200-202608-00000001
- Researchers have discovered 3 high-risk security vulnerabilities in multiple VMware products (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), categorized as Out-of-Bounds Write, Authentication Bypass, and Path Traversal, respectively. Please confirm and patch as soon as possible.
- CVE-2026-47876: An attacker who has obtained local administrator privileges on the VMXNET3 network adapter of a virtual machine can execute arbitrary code on the ESXi host. CVE-2026-59309: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to bypass authentication without authorization and access the system.
- CVE-2026-59310: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to execute arbitrary code.
- Affected Platforms:
- VMware Cloud Foundation versions 5.x prior to 8.0 U3k
- VMware Cloud Foundation and VMware vSphere Foundation versions 9.0.x.x
- VMware Cloud Foundation and VMware vSphere Foundation versions 9.1.x.x
- VMware vCenter 8.0
- VMware Telco Cloud Platform version 3.0
- VMware Telco Cloud Platform versions 4.x
- VMware Telco Cloud Platform versions 5.0.x
- VMware Telco Cloud Platform versions 5.1.x
- VMware Telco Cloud Infrastructure version 3.0
- VMware ESX version 8.0
- Recommendations:
- The vendor has released security updates for these vulnerabilities. Please refer to the official advisory to apply updates, available at: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- References:
Computer and Communication Center
Network System Division