Broadcom's latest security advisory patches five vulnerabilities across the VMware estate, three of them critical, touching ESX, vCenter, Workstation, Fusion, Cloud Foundation and Telco Cloud products. For UK data centres, the real question isn't whether to patch — it's how fast, and what to do if entitlement status stands in the way.
View the data behind this chart
| CVE-2025-22224 | CVE-2025-22225 | CVE-2025-22226 | |
|---|---|---|---|
| CVSS Score | CVSS9.3 | CVSS8.2 | CVSS7.1 |
What Broadcom just fixed in VMSA-2026-0006
Broadcom's VMSA-2026-0006 advisory addresses five vulnerabilities spanning VMware ESX, vCenter, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform and Telco Cloud Infrastructure. Three of the five carry a critical rating, according to Network World's reporting on the bulletin. That concentration of critical flaws across both the hypervisor and the management plane makes this one of the more consequential VMware patch cycles this year, and it lands at a moment when many UK organisations are still weighing up their long-term VMware strategy through navigating VMware after Broadcom's acquisition.
The scope matters for planning purposes: this isn't a niche fix limited to one edge-case configuration. It reaches core vSphere infrastructure, telco-grade deployments, and the desktop virtualisation tools many engineering teams run day to day.
The three critical CVEs to prioritise first
CVE-2026-59309 affects the VMware Directory Service and could let an attacker bypass authentication when accessing vCenter — a serious issue given vCenter's role as the single management point for an entire virtual estate. CVE-2026-47876 is an out-of-bounds write in ESXi's VMXNET3 virtual network adapter, which could allow a malicious actor to execute code on the host; it does not affect non-VMXNET3 adapters, so teams should check their virtual NIC configuration before assuming exposure. CVE-2026-59310 hits vCenter's Syslog server, giving a network-positioned attacker a path to arbitrary code execution.
Two further issues round out the advisory at lower severity. CVE-2026-41703, rated high rather than critical, covers multiple products — ESX, vCenter, Workstation and Fusion — where an attacker with VM deployment privileges could trigger an out-of-bounds read, leading to information disclosure or denial of service. CVE-2026-41709 is the least severe: insufficient logging in VMware ESX that could let a malicious administrator act without leaving an audit trail. It won't get you breached on its own, but it undermines forensic response if something else does.
- •CVE-2026-59309 — vCenter authentication bypass via Directory Service
- •CVE-2026-47876 — ESXi VMXNET3 out-of-bounds write, host code execution
- •CVE-2026-59310 — vCenter Syslog server, arbitrary code execution
- •CVE-2026-41703 (high) — multi-product out-of-bounds read, info leak/DoS
- •CVE-2026-41709 (lowest) — ESX logging gap, hides admin misuse
Why pre-Broadcom and legacy-licensed estates carry extra risk
UK data centres still running perpetual-licence VMware without active maintenance and support are in a materially different position than fully subscribed customers. Broadcom has previously confirmed that legacy licence holders would still receive critical security patches for supported products, but delivered on a separate cycle — and reporting has shown some customers with expired entitlements unable to pull fixes from the support portal immediately, with delays cited at up to 90 days. In a cycle carrying three critical CVEs, that gap is not academic.
Broadcom has also pushed customers on older ESXi 6.5 and 6.7 branches to move to vSphere 8, since older versions past general support aren't evaluated with the same rigour against new advisories. UK buyers running those older branches should treat this cycle as a forcing function to decide between VMware renewal or migration rather than patch and hope.

Patch fast, then decide the bigger question
The immediate task is straightforward: apply the VMSA-2026-0006 fixes across ESX and vCenter estates, prioritising the three critical CVEs, and confirm VMXNET3 adapter exposure before assuming CVE-2026-47876 doesn't apply. Teams supporting the actual patching workload should lean on vulnerability management solutions to track which hosts and vCenter instances remain unpatched, particularly in larger estates where Telco Cloud Platform or Cloud Foundation deployments span multiple sites.
The bigger question is strategic. Repeated critical-severity cycles, combined with licence-entitlement friction, have already pushed some organisations toward subscription upgrades or supported second-user licences just to keep a clean patch path. Others are using the moment to model an exit. If your organisation hasn't run the numbers recently, it's worth using a tool to calculate VMware migration costs against renewal, and to weigh realistic VMware alternatives before the next advisory forces the decision under time pressure.
Building resilience beyond the patch cycle
Patching alone doesn't close the exposure window between disclosure and deployment — history shows VMware flaws get weaponised quickly once details are public, as seen in the actively exploited March 2025 set. UK teams should pair rapid patching with layered controls: network segmentation and zero trust principles to limit lateral movement from a compromised host, and managed detection & response to catch exploitation attempts against vCenter or ESXi before they escalate. Organisations still running unsupported or end-of-support VMware branches without a clear upgrade budget should also look at third-party maintenance for IT infrastructure as a bridge while a migration or renewal decision is finalised.
- 01Network World — Broadcom patches vulnerabilities all over VMware · 30 July 2026
- 02The Hacker News — Three critical VMware flaws allow auth bypass · 29 July 2026
- 03Computer Weekly — VMware patches put spotlight on support · 30 July 2026
- 04Ars Technica — Some VMware perpetual license owners are unable to download security patches · 23 July 2025
- 05The Register — VMware portal prevents some users from downloading patches · 23 July 2025
- 06IBM X-Force — FYSA: VMware critical vulnerabilities patched · 5 March 2025
