BDS Threat Advisory: Critical Vulnerabilities in VMware vCenter Server and ESX

J Ellis July 31, 2026 Threat Notices

Overview

Our Cybersecurity SOC partner has identified five vulnerabilities affecting VMware vCenter Server and ESX, including two critical, unauthenticated vulnerabilities in vCenter and a critical guest-to-host escape affecting the VMXNET3 virtual network adapter. Patches are available for all affected versions.

Vulnerability Details

  • CVE-2026-59309 | CVSS 9.8 | vCenter Authentication Bypass Vulnerability — An unauthenticated attacker with network access to vCenter can bypass authentication in the VMware Directory Service and gain unauthorized access to the system.
  • CVE-2026-59310 | CVSS 9.8 | vCenter Directory Traversal / Remote Code Execution Vulnerability — An unauthenticated attacker with network access to vCenter can exploit a directory traversal flaw in the Syslog server to execute arbitrary code.
  • CVE-2026-47876 | CVSS 9.3 | ESX VMXNET3 Out-of-Bounds Write Vulnerability — A threat actor with local administrative privileges on a VM using the VMXNET3 adapter can trigger an out-of-bounds write to execute code on the underlying ESX host. Non-VMXNET3 adapters are not affected.
  • CVE-2026-41703 | CVSS 7.6 — Allows information disclosure or denial-of-service via an out-of-bounds read.
  • CVE-2026-41709 | CVSS 2.7 — Allows a malicious administrator to perform unlogged operations.

How Could This Be Exploited?

vCenter and ESX are administrative platforms that provide broad control across enterprise virtual environments, making them attractive targets for threat actors. An attacker who successfully exploits the authentication bypass or directory traversal vulnerabilities could gain unauthorized access to vCenter and execute code remotely, without needing valid credentials. Once compromised, these systems can be abused to expand access, move laterally, or execute malicious actions using legitimate administrative functionality. The VMXNET3 vulnerability could allow a user with local administrative privileges inside a VM to break out and execute code directly on the underlying host.

Is There Active Exploitation?

As of publication, there is no publicly reported evidence of active exploitation for any of the five vulnerabilities. However, given the severity (two rated CVSS 9.8) and the unauthenticated nature of the primary vCenter flaws, organizations should treat this as a high-priority patching item.

What We’re Doing

Our Cybersecurity SOC partner focuses on identifying the post-compromise behaviors commonly associated with abuse of trusted management platforms like vCenter and ESX. Their team continues to monitor for signs of exploitation and will provide updates as new information becomes available.

Recommendations

  • Immediate Action: Apply the Broadcom-released patches for affected vCenter and ESX versions as documented in the response matrix.
  • Restrict administrative and network access to vCenter Server to trusted management networks only.
  • Restrict VM administrative privileges to trusted personnel to reduce the risk of VMXNET3 exploitation.
  • Monitor vCenter authentication logs and Syslog activity for unexpected access or configuration changes.
  • Verify patch deployment across all managed vSphere and vCenter environments.

References

Questions or Concerns?

If you have any questions about this advisory or would like help verifying your patch status, please contact your Black Diamond Solutions account team.