Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for critical VMware vCenter and ESXi vulnerabilities rated CVSS 9.8

Broadcom has released emergency patches for five vulnerabilities across VMware vCenter, ESXi, Workstation, and Fusion. Three of the five are rated critical, and two carry a CVSS score of 9.8 out of 10.

The worst of them, CVE-2026-59309, is an authentication bypass in VMware Directory Service. An unauthenticated attacker with network access to vCenter can skip login entirely and take full control. The second, CVE-2026-59310, is a directory-traversal flaw in the vCenter Syslog server that lets a remote attacker execute arbitrary code. The third critical issue, CVE-2026-47876, is a VM escape — an attacker with admin privileges inside a virtual machine using the VMXNET3 adapter can break out and run code on the ESXi host itself.

Why This Matters for Australian Businesses

VMware environments are bread and butter for mid-market businesses and their MSPs. If your organisation runs virtualised servers — and most do — there’s a decent chance vCenter or ESXi is underneath them. Ransomware crews have been building dedicated VMware encryptors for years because compromising a single ESXi host can give them access to dozens of servers in one hit. Broadcom hasn’t seen exploitation in the wild yet, but with proof-of-concept details circulating, that window won’t stay open long.

What we see across our client base is that VMware patching often lags behind Windows and application updates. It’s treated as infrastructure — stable, set and forget. That mindset is exactly what makes CVSS 9.8 flaws dangerous. A vCenter server sitting unpatched on the network is a single point of compromise for your entire virtualised estate.

What to Do

Broadcom classifies these as an emergency change. There are no workarounds — patching is the only fix. Here’s the short version:

  • vCenter: Update to 9.1.0.0300, 9.0.2.0100, or 8.0 Update 3k.
  • ESXi: Update to 9.1.0.0200, 9.0.2.0100, or 8.0 Update 3k. This requires a host restart — use vMotion to migrate VMs during a rolling reboot.
  • Workstation and Fusion: Upgrade to version 26H1.
  • Cloud Foundation, Telco Cloud: Check Broadcom’s advisory for separate patching instructions.

If you’re running VMware and aren’t sure whether your environment is current, that’s the first thing to check this week. All IT Services manages VMware patching for clients across Sydney, the Central West, Brisbane, and Melbourne — get in touch if you need a hand.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →