⚡️ 0-Day Alert: VMware ESXi + vCenter

VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors.

VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).

Two attack vectors:

1. Remote attack on vCenter –

CVE-2026-59309: auth bypass via network access

CVE-2026-59310: directory traversal RCE

An exploit would allow control of entire ESXi infrastructure.

2. A VM-escapable set of two bugs –

CVE-2026-59310: vmxnet3 OOBW

CVE-2026-41703: core OOBR

These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.

Diffing and exploiting (1) is straightforward and should be patched promptly.