UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Broadcom VMware Critical Patches 2026: UK Buyer Guide

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Broadcom's latest security advisory patches five vulnerabilities across the VMware estate, three of them critical, touching ESX, vCenter, Workstation, Fusion, Cloud Foundation and Telco Cloud products. For UK data centres, the real question isn't whether to patch — it's how fast, and what to do if entitlement status stands in the way.

CVSS Severity of Actively Exploited 2025 VMware Flaws
10 CVSS8 CVSS5 CVSS3 CVSS0 CVSS9.3 CVSSCVE-2025-222248.2 CVSSCVE-2025-222257.1 CVSSCVE-2025-22226CVSS Score
View the data behind this chart
CVSS Severity of Actively Exploited 2025 VMware Flaws
CVE-2025-22224CVE-2025-22225CVE-2025-22226
CVSS ScoreCVSS9.3CVSS8.2CVSS7.1

What Broadcom just fixed in VMSA-2026-0006

Broadcom's VMSA-2026-0006 advisory addresses five vulnerabilities spanning VMware ESX, vCenter, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform and Telco Cloud Infrastructure. Three of the five carry a critical rating, according to Network World's reporting on the bulletin. That concentration of critical flaws across both the hypervisor and the management plane makes this one of the more consequential VMware patch cycles this year, and it lands at a moment when many UK organisations are still weighing up their long-term VMware strategy through navigating VMware after Broadcom's acquisition.

The scope matters for planning purposes: this isn't a niche fix limited to one edge-case configuration. It reaches core vSphere infrastructure, telco-grade deployments, and the desktop virtualisation tools many engineering teams run day to day.

The three critical CVEs to prioritise first

CVE-2026-59309 affects the VMware Directory Service and could let an attacker bypass authentication when accessing vCenter — a serious issue given vCenter's role as the single management point for an entire virtual estate. CVE-2026-47876 is an out-of-bounds write in ESXi's VMXNET3 virtual network adapter, which could allow a malicious actor to execute code on the host; it does not affect non-VMXNET3 adapters, so teams should check their virtual NIC configuration before assuming exposure. CVE-2026-59310 hits vCenter's Syslog server, giving a network-positioned attacker a path to arbitrary code execution.

Two further issues round out the advisory at lower severity. CVE-2026-41703, rated high rather than critical, covers multiple products — ESX, vCenter, Workstation and Fusion — where an attacker with VM deployment privileges could trigger an out-of-bounds read, leading to information disclosure or denial of service. CVE-2026-41709 is the least severe: insufficient logging in VMware ESX that could let a malicious administrator act without leaving an audit trail. It won't get you breached on its own, but it undermines forensic response if something else does.

  • CVE-2026-59309 — vCenter authentication bypass via Directory Service
  • CVE-2026-47876 — ESXi VMXNET3 out-of-bounds write, host code execution
  • CVE-2026-59310 — vCenter Syslog server, arbitrary code execution
  • CVE-2026-41703 (high) — multi-product out-of-bounds read, info leak/DoS
  • CVE-2026-41709 (lowest) — ESX logging gap, hides admin misuse

Why pre-Broadcom and legacy-licensed estates carry extra risk

UK data centres still running perpetual-licence VMware without active maintenance and support are in a materially different position than fully subscribed customers. Broadcom has previously confirmed that legacy licence holders would still receive critical security patches for supported products, but delivered on a separate cycle — and reporting has shown some customers with expired entitlements unable to pull fixes from the support portal immediately, with delays cited at up to 90 days. In a cycle carrying three critical CVEs, that gap is not academic.

Broadcom has also pushed customers on older ESXi 6.5 and 6.7 branches to move to vSphere 8, since older versions past general support aren't evaluated with the same rigour against new advisories. UK buyers running those older branches should treat this cycle as a forcing function to decide between VMware renewal or migration rather than patch and hope.

Illustration: Broadcom VMware Critical Patches 2026: UK Buyer Guide

Patch fast, then decide the bigger question

The immediate task is straightforward: apply the VMSA-2026-0006 fixes across ESX and vCenter estates, prioritising the three critical CVEs, and confirm VMXNET3 adapter exposure before assuming CVE-2026-47876 doesn't apply. Teams supporting the actual patching workload should lean on vulnerability management solutions to track which hosts and vCenter instances remain unpatched, particularly in larger estates where Telco Cloud Platform or Cloud Foundation deployments span multiple sites.

The bigger question is strategic. Repeated critical-severity cycles, combined with licence-entitlement friction, have already pushed some organisations toward subscription upgrades or supported second-user licences just to keep a clean patch path. Others are using the moment to model an exit. If your organisation hasn't run the numbers recently, it's worth using a tool to calculate VMware migration costs against renewal, and to weigh realistic VMware alternatives before the next advisory forces the decision under time pressure.

Building resilience beyond the patch cycle

Patching alone doesn't close the exposure window between disclosure and deployment — history shows VMware flaws get weaponised quickly once details are public, as seen in the actively exploited March 2025 set. UK teams should pair rapid patching with layered controls: network segmentation and zero trust principles to limit lateral movement from a compromised host, and managed detection & response to catch exploitation attempts against vCenter or ESXi before they escalate. Organisations still running unsupported or end-of-support VMware branches without a clear upgrade budget should also look at third-party maintenance for IT infrastructure as a bridge while a migration or renewal decision is finalised.

Share
Key takeaways
  • VMSA-2026-0006 patches five VMware vulnerabilities; three are critical and affect ESX, vCenter and multiple related products.
  • Prioritise CVE-2026-59309 (vCenter auth bypass), CVE-2026-47876 (ESXi VMXNET3 host code execution) and CVE-2026-59310 (vCenter Syslog RCE) first.
  • Legacy perpetual-licence VMware customers without active support may face separate, slower patch delivery — check entitlement status now, not after an incident.
  • Repeated critical cycles are a strong prompt to formally compare renewal, subscription upgrade and migration rather than patch reactively each time.
Frequently asked

FAQs — Broadcom VMware Critical Patches 2026

Which VMware CVEs from VMSA-2026-0006 should UK teams patch first?

CVE-2026-59309, CVE-2026-47876 and CVE-2026-59310 carry critical ratings and should be prioritised, followed by the high-severity CVE-2026-41703 and the lower-severity logging gap CVE-2026-41709.

Does CVE-2026-47876 affect all ESXi virtual network adapters?

No. It's specific to the VMXNET3 virtual network adapter; non-VMXNET3 adapters are not affected, so checking adapter configuration first can narrow the exposed host list.

Will Broadcom still patch VMware for customers without active support contracts?

Broadcom has said legacy licence holders without active maintenance still receive critical patches for supported products, but reporting shows this can run on a separate, slower cycle — some customers with expired entitlements have faced download delays of up to 90 days.

Is this a good moment to reassess VMware licensing strategy?

Given the frequency of critical-severity VMware cycles and ongoing licence-entitlement friction, many UK buyers are using advisories like this one to formally compare renewal, subscription upgrade and migration options rather than deciding under pressure.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111