Critical Buffer Overflows in VMware and FreeIPMI Expose Systems to Remote Code Execution

Critical Buffer Overflows in VMware and FreeIPMI Expose Systems to Remote Code Execution

First seen 6 Sep 2026, 03:58 UTC Ciberseguridadlatam 72.5

Article Content

Browse articles
ThreatCluster

Broadcom has patched a critical vulnerability, CVE-2026-59346, in VMware Workstation and Fusion, allowing local attackers with elevated privileges to execute arbitrary code. This integer overflow vulnerability scores 9.3 on the CVSS scale. Concurrently, CVE-2026-85506 and CVE-2026-85509 in FreeIPMI expose Dell iDRAC servers to remote code execution, affecting versions prior to 1.6.19. Attackers can exploit these vulnerabilities through specific commands or malformed data responses from compromised baseboard management controllers (BMCs). The vulnerabilities are critical due to their potential impact on data centers, especially in Latin America, where Dell servers are widely used. Patches for both FreeIPMI vulnerabilities were released on September 4, 2026, and administrators are urged to update their systems immediately.

Key Points: • CVE-2026-59346 allows local code execution in VMware with elevated privileges. • CVE-2026-85506 and CVE-2026-85509 expose Dell iDRAC servers to remote code execution. • Patches for all vulnerabilities were released on September 4, 2026; immediate updates are recommended.

Ask AI about this cluster

Timeline

2026-09-04
Patches released for FreeIPMI vulnerabilities
FreeIPMI versions 1.6.19 and later address CVE-2026-85506 and CVE-2026-85509, fixing critical buffer overflow issues.
Ciberseguridadlatam
2026-09-04
CVE-2026-59346 disclosed
Broadcom announced a critical integer overflow vulnerability in VMware Workstation and Fusion, allowing local code execution.
Ciberseguridadlatam
2026-09-04
CVE-2026-85509 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-04
CVE-2026-85506 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-06
Current status of vulnerabilities
Administrators are urged to apply patches for vulnerabilities in VMware and FreeIPMI to mitigate risks.
Ciberseguridadlatam