Broadcom has released emergency patches for multiple critical VMware vulnerabilities affecting vCenter and ESXi. The most severe issues allow unauthenticated attackers to bypass authentication, execute arbitrary code, and, in certain scenarios, escape from a guest VM to the underlying hypervisor. The key vulnerabilities include: CVE-2026-59309 (CVSS 9.8): Authentication bypass in the VMware Directory Service. CVE-2026-59310 (CVSS 9.8): Directory traversal in the vCenter Syslog Server that can lead to remote code execution. Additional ESXi issues may enable host compromise from a guest VM under specific conditions. An attacker with network access to a vulnerable vCenter instance could potentially gain full administrative control without valid credentials, then deploy malware, steal credentials, manipulate virtual infrastructure, or pivot across enterprise deployments


