:

VMWARE PATCHES CRITICAL FLAWS IN AUTH, VM ESCAPE

INDUSTRY DESK1 MIN READ
THU, JUL 30, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Broadcom has released security updates addressing five vulnerabilities across VMware products, including three critical flaws that enable authentication bypass and virtual machine escapes to the host system.

The vulnerabilities affect VMware vCenter, ESX, Workstation, and Fusion. The three critical issues allow attackers to bypass authentication, execute arbitrary code, and escape from virtual machines to gain access to the underlying host. VMware users should apply patches immediately to affected systems. The fixes address a range of severity levels, with the critical flaws presenting the highest risk to enterprise infrastructure and individual users running virtualized environments. Details on specific vulnerability identifiers and affected versions are available through Broadcom's official security advisory. Organizations running VMware infrastructure should prioritize patching to prevent potential exploitation. The company has not reported active exploitation of these flaws in the wild at this time. This update follows Broadcom's acquisition of VMware and its ongoing responsibility for maintaining security across the virtualization platform's product suite.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

2H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

4H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

9H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.