Digital.Nhs.Uk
Critical Vulnerabilities in VMware Products Require Immediate Patching
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Broadcom has released VMSA-2026-0006 addressing multiple critical vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion. The vulnerabilities, including CVE-2026-59309 and CVE-2026-59310, could allow arbitrary code execution and authentication bypass. Affected systems include VMware vCenter Server, VMware Workstation, and VMware Cloud Foundation. Organizations are urged to apply the patches immediately to mitigate risks. The vulnerabilities were privately reported and have been assigned a maximum CVSSv3 base score of 9.8. Failure to patch could lead to unauthorized access and potential data breaches. Broadcom acknowledged the researchers who reported these issues. The advisory emphasizes the urgency of applying the updates.
Key Points: • Multiple critical vulnerabilities in VMware products require immediate patching. • CVE-2026-59309 and CVE-2026-59310 have a CVSS score of 9.8, indicating high severity. • Affected systems include VMware ESX, vCenter, Workstation, and Fusion.