■■□□□ VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).
Two attack vectors:
1. Remote attack on vCenter –
CVE-2026-59309: auth bypass via network access
CVE-2026-59310: directory traversal RCE
An exploit would allow control of entire ESXi infrastructure.
2. A VM-escapable set of two bugs –
CVE-2026-59310: vmxnet3 OOBW
CVE-2026-41703: core OOBR
These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.
https://x.com/i/status/2082869868823752811
