HIGH
VMware Patches Three Critical Flaws Allowing Auth Bypass, VM Escapes
Broadcom released security updates fixing five vulnerabilities across VMware vCenter, ESX, Workstation, and Fusion. Three of the flaws are rated critical and allow attackers to bypass authentication, execute arbitrary code, or escape from a guest VM to the host.
No public reports of active exploitation accompanied the disclosure. Administrators running affected VMware products should apply Broadcom’s patches promptly — VM escape bugs are high-value targets in virtualized and cloud environments.