Header image overlay

Critical vulnerabilities in VMware vCenter Server and ESX

Our experts keep you up-to-date on critical cyber threats (CVEs)

VMware released a new security update on 29 July 2026 for multiple vulnerabilities in VMware vCenter Server, ESX, Workstation and Fusion. Some of these vulnerabilities are very critical and require the prompt installation of the available updates.

Critical vulnerabilities in VMware vCenter Server and ESX

Critical vulnerabilities in VMware vCenter Server and ESX

VMware released a new security update on 29 July 2026 for multiple vulnerabilities in VMware vCenter Server, ESX, Workstation and Fusion. Some of these vulnerabilities are very critical and require the prompt installation of the available updates.

Vulnerability 1 – VMware vCenter Server

Two critical vulnerabilities with a CVSS score of 9.8 have been identified in VMware vCenter Server:

  • CVE-2026-59309
  • CVE-2026-59310

An attacker with network access to the vCenter Server could potentially exploit these vulnerabilities to bypass authentication and gain unauthorised access to the system.

In addition, a vulnerability in the Syslog functionality could allow for arbitrary code execution on the vCenter Server. This could potentially allow an attacker to gain control of the system and the underlying virtual infrastructure.

Vulnerability 2 – VMware ESX

A critical vulnerability has also been identified in the VMware ESX hypervisor:

  • CVE-2026-47876
  • CVSS-score: 9.3

Misuse of this vulnerability could jeopardise the security of the hypervisor and the virtual environments running on it.

VMware has also resolved some less critical vulnerabilities in ESX, vCenter Server, Workstation and Fusion.

Source and additional information

The vulnerabilities are described in the security advisory VMSA-2026-0006, published by VMware on 29 July 2026.

There is currently no workaround available. Only official security updates from VMware will resolve these vulnerabilities.

Take action

The above vulnerabilities are highly critical. We therefore recommend installing the available updates as soon as possible.

Clients with a Managed Services contract will be provided with the necessary updates by VanRoey.

If you do not want us to automatically upgrade your environment, please contact us in good time.

You don't have a Managed Services contract, but you want our experts to carry out updates? You can also contact our support department for this.

Need help?

Contact us to review the impact on your VMware environment or to perform the necessary updates.

This can be done via:

Create a ticket

Can't create tickets? Ask here to get an account. If our Engineer needs to remotely control your PC, he or she will ask you to run this software .

Receive our newsletter including invitations to events & interesting industry news!

Receive alerts from current CVEs and tips to remedy them!

By registering, you agree to our privacy policy.

As we prepare for the Dynamate rebrand & merger, you can immerse yourself in, amongst other things,. AI, Cybersecurity, Business Applications...