

Affected Environment
VMware ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure deployments.
Threat Overview
Five vulnerabilities including a critical vCenter authentication bypass and directory traversal flaw enabling full system compromise.
Exposure Timeline
Privately reported to Broadcom; patches released the same day as disclosure, 29 July 2026, ahead of public exploitation.
Attack Surface
Network accessible vCenter Directory Service and Syslog server; VMXNET3 virtual adapter reachable from guest VM administrative access.
Technical Root Cause
Authentication bypass in VMware Directory Service and unchecked directory traversal in the Syslog server component.
Exploitation Pathway
Network attacker bypasses vCenter authentication, or a local admin abuses VMXNET3 to execute code on the host.
Operational Impact
Unauthorized vCenter access, arbitrary code execution, information disclosure, or denial of service across virtualized production environments.
Strategic Impact
Compromise of vCenter threatens the entire virtualization layer, risking cascading control over hosted workloads and data.
Required Mitigation
Upgrade all affected VMware products to fixed versions immediately; prioritize vCenter, ESXi, Cloud Foundation, and Telco platforms.
Incident Response Guidance
Review vCenter authentication and Syslog logs for anomalies; apply least privilege and monitor VM administrative activity.
References
Broadcom Security Advisory
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




