Ciberseguridadlatam
Critical Buffer Overflows in VMware and FreeIPMI Expose Systems to Remote Code Execution
Article Content
Broadcom has patched a critical vulnerability, CVE-2026-59346, in VMware Workstation and Fusion, allowing local attackers with elevated privileges to execute arbitrary code. This integer overflow vulnerability scores 9.3 on the CVSS scale. Concurrently, CVE-2026-85506 and CVE-2026-85509 in FreeIPMI expose Dell iDRAC servers to remote code execution, affecting versions prior to 1.6.19. Attackers can exploit these vulnerabilities through specific commands or malformed data responses from compromised baseboard management controllers (BMCs). The vulnerabilities are critical due to their potential impact on data centers, especially in Latin America, where Dell servers are widely used. Patches for both FreeIPMI vulnerabilities were released on September 4, 2026, and administrators are urged to update their systems immediately.
Key Points: • CVE-2026-59346 allows local code execution in VMware with elevated privileges. • CVE-2026-85506 and CVE-2026-85509 expose Dell iDRAC servers to remote code execution. • Patches for all vulnerabilities were released on September 4, 2026; immediate updates are recommended.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.