Lead story
Broadcom Patches a VM Escape in VMware ESXi — and Two Other Critical Flaws You Probably Also Missed
If you run VMware in your environment — and a significant chunk of the world's enterprise and government infrastructure does — this week's Broadcom patch drop deserves your full attention. The company released fixes for five vulnerabilities across VMware ESXi, vCenter, Workstation, and Fusion. Three of them are rated critical, and one of them lets an attacker break out of a virtual machine entirely.
That last part is the headline. A VM escape — tracked as CVE-2026-59309 — isn't just a bad vulnerability; it's a category of bad. The entire promise of virtualisation is that workloads are isolated from each other and from the host. A working VM escape tears that promise in half. An attacker who has already compromised one virtual machine on a shared host can, in theory, reach across to other VMs or the hypervisor itself. In multi-tenant environments, cloud platforms, and managed service providers, that's a catastrophic blast radius.
The second critical flaw (CVE-2026-59309, CVSS 9.8) is an authentication bypass in VMware vCenter. vCenter is the management plane for most enterprise VMware deployments — it's the thing that controls everything else. A malicious actor with nothing more than network access to vCenter could bypass authentication entirely. No credentials required. That kind of flaw typically gets weaponised quickly once a PoC surfaces.
Broadcom hasn't confirmed active exploitation of these specific flaws yet, but the history of VMware vulnerabilities is not encouraging on that front. The company's ESXi ransomware wave in 2023, the vCenter exploits in 2024 and 2025 — VMware's management layer has become a reliable target for sophisticated actors because the reward for successful exploitation is so high.
What to do. Patch. Now. If you're running any affected version of ESXi, vCenter, Workstation, or Fusion, Broadcom's security advisory has the relevant update paths. If you can't patch immediately — and in complex enterprise environments, emergency patching isn't always trivial — the priority order should be: vCenter first (authentication bypass, network-accessible), ESXi second (VM escape), then Workstation and Fusion.
Also worth reviewing: network access controls around your vCenter management interfaces. These systems should not be reachable from general corporate networks, let alone the internet. If they are, a patching delay becomes an active risk.
The Australian angle. VMware underpins a substantial portion of Australia's enterprise and government virtualisation stack. Several agencies covered under the Security of Critical Infrastructure Act run VMware environments for workloads that span both operational technology and IT. The Australian Signals Directorate has flagged VMware vulnerabilities in previous Essential Eight guidance. Expect the ASD's ACSC to issue an advisory — if they haven't already — given the critical severity ratings and the breadth of affected products.
The broader pattern here is worth noting: we've had Oracle's 1,449-patch mega-drop last Friday, and now Broadcom serving up VM escapes and auth bypasses on a Wednesday. Patch fatigue is real, but so is the adversary backlog building up every week teams fall behind.
