⚡️ 0-Day Alert: VMware ESXi + vCenter
VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors.
VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).
Two attack vectors:
1. Remote attack on vCenter –
CVE-2026-59309: auth bypass via network access
CVE-2026-59310: directory traversal RCE
An exploit would allow control of entire ESXi infrastructure.
2. A VM-escapable set of two bugs –
CVE-2026-59310: vmxnet3 OOBW
CVE-2026-41703: core OOBR
These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.
Diffing and exploiting (1) is straightforward and should be patched promptly.