Výsledky hledání

výrobce: VMware× v celém archivu zrušit filtry

12 karet z 14 položek CZ · EN/orig

1

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]

KEV ✓ · ransomware EPSS 0.50 CVE-2024-37079 CVE-2025-22225 CVE-2025-60710 CVE-2026-22719 CVE-2026-59310 VMware US

tg: zneužíváno tg: zranitelnost tp: ransomware

· BleepingComputer · CISA: Critical VMware RCE flaw now exploited by ransomware gangs

2

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.

CVSS 7.5 CVE-2026-59346 VMware US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

SPOJENO PŘES CVE VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.3, CVEs: CVE-2026-59346, CVE-2026-59347, Summary: An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products. VMXNET3 integer-overflow vulnerability (CVE-2026-59346) CVSSv3.1: 9.3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H A malicious actor with local…

CVSS 9.3 CVE-2026-59346 CVE-2026-59347 Broadcom VMware FI FR IT

tg: zranitelnost

· NCSC-FI · VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) · CERT-FR – avis · Multiples vulnérabilités dans les produits VMware (04 septembre 2026) · CSIRT Itálie (ACN) · Risolte vulnerabilità in VMware Workstation e Fusion

1

1

VMware security advisory (AV26-763) – Update 1

Serial number: AV26-763Date: July 30, 2026Updated: August 18, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-25557999 Prior to ESXi80U3i-25205845 Prior to ESXi80U3k-25595708 Fusion Prior to 26H1 Telco Cloud Infrastructure 3.0 Telco Cloud Platform 4.x 5.0.x 5.1.x Workstation Prior to 26H1 vCenter Prior to 8.0…

KEV ✓ · ransomware EPSS 0.50 CVE-2026-41703 CVE-2026-41709 CVE-2026-47876 CVE-2026-59309 CVE-2026-59310 VMware CA

· Cyber Centre Kanada · VMware security advisory (AV26-763) – Update 1

1

3

Vulnerabilità in prodotti VMware

Broadcom ha rilasciato aggiornamenti di sicurezza per risolvere alcune nuove vulnerabilità, di cui 3 con gravità “critica” e una con gravità “alta”, in vari prodotti della suite VMware. Tali vulnerabilità, qualora sfruttate, potrebbero consenti ad un utente malintenzionato remoto di eludere i meccanismi di autenticazione, elevare i propri privilegi ed eseguire codice arbitrario sui sistemi interessati.

KEV ✓ · ransomware EPSS 0.50 CVE-2026-41703 CVE-2026-47876 CVE-2026-59309 CVE-2026-59310 Broadcom VMware IT

· CSIRT Itálie (ACN) · Vulnerabilità in prodotti VMware

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 …

KEV ✓ · ransomware EPSS 0.50 CVSS 9.8 CVE-2026-59309 CVE-2026-59310 CVE-2026-593109 VMware Broadcom US

· Rapid7 · Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

1

ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.

EPSS 0.00 CVSS 8.2 CVE-2026-47876 VMware US

· Zero Day Initiative · ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability

1

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…

Red Hat Microsoft OpenAI VMware US

· ZDI Blog · Pwn2Own Berlin 2026: Day Three Results and Master of Pw

1

Announcing Pwn2Own Berlin for 2026

If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of our shipping troubles, we had an amazing time and can’t wait to get back.Last year, we added Artificial Intelligence as a category with great results. This year, we’re expanding this and splitting it…

Microsoft VMware Adobe AWS US

· ZDI Blog · Announcing Pwn2Own Berlin for 2026