【Vulnerability Alert】Multiple VMware Products Contain Three High-Risk Security Vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310). Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-08-07 update date : 2026-08-07

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026080301080404 Publication Time 2026-08-03 13:38:05
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-03 13:38:05
Impact Level Middle  
[Subject]
【Vulnerability Alert】Multiple VMware Products Contain Three High-Risk Security Vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202608-00000001

Researchers discovered that multiple VMware products contain three high-risk security vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), which are classified as Out-of-Bounds Write, Authentication Bypass, and Path Traversal vulnerabilities, respectively. Please confirm and apply patches as soon as possible.

CVE-2026-47876: An attacker who has obtained local administrator privileges on a virtual machine's VMXNET3 adapter may execute arbitrary code on the ESXi host.

CVE-2026-59309: A remote attacker who has obtained network access to VMware vCenter may exploit this vulnerability to bypass authentication and access the system without authorization.

CVE-2026-59310: A remote attacker who has obtained network access to VMware vCenter may exploit this vulnerability to execute arbitrary code.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

VMware Cloud Foundation versions 5.x to versions prior to 8.0 U3k

VMware Cloud Foundation and VMware vSphere Foundation versions 9.0.x.x

VMware Cloud Foundation and VMware vSphere Foundation versions 9.1.x.x

VMware vCenter 8.0

VMware Telco Cloud Platform version 3.0

VMware Telco Cloud Platform versions 4.x

VMware Telco Cloud Platform versions 5.0.x

VMware Telco Cloud Platform versions 5.1.x

VMware Telco Cloud Infrastructure 3.0

VMware ESX version 8.0

[Recommended Actions]

The official vendor has released remediation updates for the vulnerabilities. Please refer to the official instructions for updating. The URL is as follows:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-47876
2. https://nvd.nist.gov/vuln/detail/CVE-2026-59309
3. https://nvd.nist.gov/vuln/detail/CVE-2026-59310
4. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center