Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical Vulnerabilities in VMware Products

Broadcom has released security updates to address multiple vulnerabilities affecting VMware products including VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion and others. Three of these vulnerabilities are classified as critical and identified as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, which could allow attackers to compromise affected VMware environments.


 

Affected Systems

 

The affected VMware products include, but are not limited to:

  • VMware vCenter Server: versions 9.1.x before 9.1.0.0300, 9.0.x before 9.0.2.0100, and 8.0 before Update 3k.
  • Vmware ESXi: versions 9.1.x before 9.1.0.0200‑25557999, 9.0.x before 9.0.2.0100‑25595025, and 8.0 before Update 3k.
  • VMware Workstation and VMware Fusion: version 25H2.
 

Security Risks

 

Exploitation of these vulnerabilities could let attackers bypass authentication, run unauthorized commands, or break out of a virtual machine to gain control of the ESXi host. This may result in complete compromise of affected VMware environments.

 

Recommended Actions

 

The National Cyber Security Authority (NCSA) strongly recommends to system administrators to:

 

1. Follow VMware Security Advisory (Broadcom VMSA-2026-0006) to lower the risk of potential exploits, protect systems, and ensure their security.

 

2. Apply the required and latest security updates as soon as possible.



The released software versions to upgrade to include, but are not limited to:
 

3. Before any update task, please ensure you have a recent backup that can easily be restored.

 


For further information and support, please contact NCSA by email at rwcsirt@ncsa.gov.rw or call us on 9009.

 

References

04 August 2026

© 2026 National Cyber Security Authority