Broadcom Patches Critical VMware Auth Bypass, RCE, VM Escape
Broadcom shipped security updates for VMware vCenter, ESX, Workstation, and Fusion covering three critical flaws including a CVSS 9.8 no-auth bypass. Patch now.
Broadcom has shipped security updates for VMware ESX, vCenter, Workstation, and Fusion. Three of the patched vulnerabilities are rated critical: an authentication bypass, a remote code execution flaw, and a VM escape. All three need patches.
The most urgent is an authentication bypass in vCenter rated CVSS 9.8. No credentials required — an attacker with network access to vCenter can exploit it directly. In most enterprise environments, vCenter manages the entire virtual estate: ESXi hosts, VMs, storage, networking. Compromise at that layer isn’t limited to one system.
The other two critical-severity issues affect the broader VMware platform. A code execution vulnerability is catalogued separately. The VM escape carries its own weight on any shared or multi-tenant infrastructure where guest isolation is part of the security model.
The Hacker News reports that Broadcom’s advisory covers all three flaws across ESX, vCenter, Workstation, and Fusion. Specific affected version ranges and fixed releases are in the advisory — check Broadcom’s security advisories page for version-by-version patch guidance before starting your rollout.
What to do
- Pull your VMware inventory. Which versions of vCenter, ESXi, Workstation, and Fusion are running? The advisory lists affected version ranges and the fixed releases.
- Patch vCenter first. No-auth CVSS 9.8 is the immediate priority. If your vCenter management interface is reachable from any broad network segment — including internal lateral-movement ranges — this is urgent.
- Patch hypervisor hosts alongside it. The code execution and VM escape flaws apply independent of vCenter exposure. An attacker with a guest VM foothold can attempt the escape path.
- Audit network access to vCenter. Management planes should not be internet-exposed. If yours is, that’s a separate problem that predates this advisory and needs to be fixed in parallel, not after.
Priority call
Patch vCenter this week. Patch ESXi alongside it. Workstation and Fusion matter more if they’re on shared development systems with production network access — the VM escape flaw narrows the “it’s just a dev box” reasoning considerably.
Three criticals in one advisory across the core virtualization stack is not a next-sprint situation. VMware infrastructure running unpatched against a no-credential CVSS 9.8 auth bypass isn’t hardened — it’s waiting.
Sources: The Hacker News. Prior coverage: vCenter’s Upload Bug: Don’t Expose Management Planes.
Found this useful? Share it.

