CyberWatch

Australian Unity: Critical Security Advisory – VMware Vulnerability (VMSA-2026-0006)

Written by Kyocera Document Solutions ANZ | Aug 3, 2026, 3:04:01 AM

We'd like to make you aware of multiple critical security vulnerabilities recently disclosed by Broadcom (VMSA-2026-0006) affecting VMware vCenter Server and VMware ESX/ESXi. Two of these carry a CVSS score of 9.8 and could allow an attacker with network access to fully compromise your vCenter, so we recommend prompt attention.

Summary of the Vulnerabilities:
  • CVE-2026-59309 (CVSS 9.8, Critical) – An authentication bypass in the vCenter Directory Service. An attacker with network access to vCenter can bypass authentication and gain unauthorised access.
  • CVE-2026-59310 (CVSS 9.8, Critical) – A directory traversal flaw in the vCenter Syslog service, allowing an attacker with network access to vCenter to execute arbitrary code.
  • CVE-2026-47876 (CVSS 9.3, Critical) – An out-of-bounds write in the ESX VMXNET3 virtual network adapter. An attacker with local admin rights on a guest VM (using a VMXNET3 adapter) could execute code on the host — i.e. a VM escape. VMs using non-VMXNET3 adapters are not affected.
  • CVE-2026-41703 (CVSS 7.6, Important) – An out-of-bounds read in ESX that could lead to information disclosure or a denial-of-service condition on the host process.
  • CVE-2026-41709 (CVSS 2.7, Low) – Insufficient logging in ESX that could allow a malicious administrator to perform actions without them being logged.
  • Important: There are no workarounds for any of these — patching is the only remediation.
  • Full Broadcom advisory can be found here.
What's Affected:

vCenter Server: 9.1.x, 9.0.x, and 8.0
ESX / ESXi: 9.1.x, 9.0.x, and 8.0
Since patches are cumulative, updating to the latest fixed build below remediates all five CVEs in one hit.

Recommended Action:

We strongly encourage reviewing your environment to identify affected versions and updating to the fixed builds below as soon as possible. As always, patch vCenter before your ESXi hosts.

  • vCenter 9.1.x 9.1.0.0300

  • vCenter 9.0.x 9.0.2.0100

  • vCenter 8.0 8.0 U3k

  • ESXi 9.1.x ESXi 9.1.0.0200 (build 25557999)

  • ESXi 9.0.x ESXi 9.0.2.0100 (build 25595025)

  • ESXi 8.0 ESXi 8.0 U3k (build 25595708)

Once a vulnerability and its patch are publicly disclosed, attackers commonly attempt to reverse-engineer the fix to target unpatched deployments, so prompt patching matters here.

Please Note: If you are using 3rd party applications like Zerto Replication, then you will need to wait until these updates are supported before patching.

 

At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com