Cybersecurity & Protection

VMware ESXi, vCenter and More: Vulnerabilities Allow Code Execution and DoS

Oct 1, 2026 1 min read
All articles

Multiple security vulnerabilities have been disclosed in several VMware products, including ESXi, vCenter Server, Workstation and Fusion. Attackers can exploit these flaws to trigger denial of service conditions, expose sensitive information, bypass security controls, and in certain scenarios execute arbitrary code.

Which products are affected

The vulnerabilities span a wide range of the VMware product family. Flaws in ESXi and vCenter Server are particularly critical, as these systems are commonly at the center of enterprise infrastructure. Compromising them can put all virtual machines running on the platform at risk.

Recommended steps

Broadcom (VMware's parent company) has released security updates. Check the Broadcom Support Portal for affected versions of ESXi, vCenter Server, Workstation and Fusion, then install the available patches. Since VMware infrastructure is often business-critical, plan patching carefully within a maintenance window.

If immediate patching is not possible, check whether VMware-provided workarounds can temporarily reduce the attack surface.