“vmware” — 47 distilled results

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347)

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system. **If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP.

CISA warns of active exploitation of critical infrastructure flaws

Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.

Multiple critical cybersecurity vulnerabilities disclosed

Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.

Mixed Cybersecurity Alerts and Breaches

Six unrelated security stories: VMware ESXi critical patch, AI-enhanced phone fraud, US humanoid robot ban, MCP bridge vulnerability, Analog Devices data breach, and Microsoft phishing attacks. No single coherent narrative connects these items.

Multiple Linux and network device vulnerabilities disclosed

Between September 24–26, 2026, security researchers disclosed six significant CVE vulnerabilities: three in Linux Kernel (CVE-2026-93215, CVE-2026-93224, CVE-2026-93789, CVE-2026-98163), one in D-Link DIR-895L router (CVE-2026-100740), and one in VMware RabbitMQ (CVE-2026-67411). All carried elevated or severe severity ratings.