Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape
Broadcom patched five CVEs in VMware vCenter, ESXi, Workstation, and Fusion. Three are critical: auth bypass, RCE, VM escape. Patch vCenter now.
Broadcom published a security advisory on July 30 covering five vulnerabilities across VMware vCenter Server, ESXi, Workstation, and Fusion. Three of the five are rated critical: an authentication bypass, a remote code execution flaw, and a VM escape. BleepingComputer’s disclosure summary has the rundown; Broadcom’s security advisory portal has the full CVE list and affected version tables.
Patches are available now. There’s no productive reason to wait.
What you’re actually dealing with
Three critical flaws in the same advisory is already a bad headline. The combination is worse.
An authentication bypass in vCenter means an unauthenticated attacker who can reach your management plane can get in. That’s the entry. The remote code execution is what they do once they’re past the door. A VM escape is how they then break out of a compromised guest and gain code execution on the ESXi host itself — and from there, lateral access to every other VM that host is running.
Chained, those three findings describe a path from “attacker can reach your vCenter endpoint” to “attacker owns your entire virtual estate.” That chain isn’t theoretical. It’s the documented playbook for targeted ESXi attacks, and this advisory just handed it a new on-ramp.
vCenter and ESXi are the obvious priorities, but the advisory covers Workstation and Fusion too. Developer workstations with internal network access are not out of scope.
What to actually do
Patch vCenter first. It’s the management plane for your whole virtual environment and the authentication bypass is your widest exposure. Pull the advisory from Broadcom’s security portal, match your build against the fixed versions, and schedule the downtime.
Check ESXi next. The VM escape affects hypervisor hosts. Prioritize hosts running internet-facing workloads or multi-tenant guests — those have the highest blast radius if containment breaks. ESXi patching requires maintenance mode for each host; plan for this now, not when you’re under pressure.
Workstation and Fusion after that. They run on endpoint hardware, which usually means less lateral movement exposure than a datacenter ESXi host — but developer machines with access to internal networks are not meaningless targets. Get them in the patch window.
If vCenter is internet-reachable: this is not a change-window conversation. An unauthenticated entry point into your virtual management plane does not wait. If you can’t patch immediately, restrict inbound access to the management port to known-good source IPs and shut off direct internet exposure. The restriction is temporary. The compromise risk if you skip it isn’t.
The honest timeline
Broadcom published this advisory on July 30. Scanning for VMware management ports is continuous — it was happening before this advisory dropped, and it is happening right now. The window between an advisory publication and the first exploitation attempts against unpatched targets is not measured in weeks anymore. It’s days, sometimes hours, and for high-profile virtualization infrastructure it’s often less.
Your vCenter build version and your ESXi host patch level are the only variables that matter here. Look them up before you read anything else today.
Priority call
Three critical findings — authentication bypass, RCE, VM escape — in a single Broadcom advisory covering your virtualization infrastructure ranks higher than anything else in your queue right now. The patches are available. The advisory is public. The targeting will follow. Get vCenter current, get ESXi into the maintenance window, and confirm Workstation and Fusion are updated on developer endpoints.
Full CVE details and fixed version tables: Broadcom security advisory portal. Summary reporting: BleepingComputer.
Found this useful? Share it.


