BoletimSecJuly 30, 2026🇵🇹Translated from Portuguese

Broadcom Patches Five Critical VMware Vulnerabilities Including CVSS 9.8 Authentication Bypass

Broadcom has issued security updates addressing five vulnerabilities in VMware products that could allow authentication bypass, code execution, and virtual machine escapes in corporate virtualized environments.

The most critical flaw, tracked as CVE-2026-59309 with a CVSS score of 9.8, affects the VMware Directory Service component of vCenter. An attacker with network access to the server can bypass authentication mechanisms and gain access without valid credentials.

Because vCenter manages hosts, virtual machines, networks, and storage, unauthorized access carries significant risk, potentially enabling infrastructure changes, service disruption, and compromise of business workloads.

Another high-severity issue, CVE-2026-47876, resides in the VMXNET3 virtual network adapter of ESX. An attacker with administrative privileges inside a virtual machine can exploit an out-of-bounds write condition to execute arbitrary code directly on the hypervisor host.

The update package also resolves an unauthorized memory read vulnerability affecting ESX, Workstation, and Fusion, as well as a logging deficiency that could allow certain administrative actions to go undetected.

No temporary mitigations are available. Administrators are advised to update vCenter to versions 9.1.0.0300, 9.0.2.0100, or 8.0 U3k, apply corresponding patches to ESX hosts and Cloud Foundation, and upgrade Workstation and Fusion to version 26H1.

Related articles

HabrVulnerabilities & Exploits

Secure Error Logging Practices to Prevent Information Leaks Across Java, Kotlin, JavaScript and Python

The article examines how improper error logging can expose sensitive details such as stack traces, file paths, library versions and database structures, enabling attackers to map applications and craft targeted exploits. It covers core logging levels from DEBUG to FATAL, mechanisms including text files, binary logs and databases, plus the roles of Trace ID and Correlation ID in tracing requests across microservices. Real-world vulnerable code examples in Flask and SQLite demonstrate direct exception output, manual traceback exposure and SQL error leakage that confirm technologies like Python 3.10 or SQLite usage. CWE categories including CWE-209, CWE-532, CWE-538 and CWE-1295 are referenced to classify risks of information disclosure through logs. Mitigation steps include stripping version headers in Nginx, sanitizing inputs with regular expressions, using OpenTelemetry for structured JSON logging and avoiding debug modes in production. The guidance stresses balancing detailed logs for incident response with protections against injection and reconnaissance.

HispasecVulnerabilities & Exploits

Cisco Releases Hotfixes for Actively Exploited CVE-2026-20316 Zero-Day in Secure FMC Allowing Static Credential Access

A zero-day vulnerability tracked as CVE-2026-20316 is being actively exploited in Cisco Secure Firewall Management Center, enabling remote attackers to authenticate using hardcoded low-privilege credentials without prior authentication. The flaw carries a CVSS score of 5.3 but has been elevated to High severity by Cisco due to its potential for chaining with other vulnerabilities to achieve privilege escalation. Cisco has issued hotfixes across multiple versions including 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 while urging administrators to inspect logs for the presence of /var/tmp/license.tmp as an indicator of compromise. The same indicator is also linked to the related critical authentication bypass CVE-2026-20079 that can lead to root access via script execution. Organizations are advised to restrict management interface exposure through ACLs, VPNs and dedicated admin networks, rotate credentials after suspected compromise, and review sudo executions and license-related commands. U.S. federal agencies have a remediation deadline of August 1, 2026 under the Known Exploited Vulnerabilities catalog.

BoletimSecVulnerabilities & Exploits

Firefox JIT Vulnerability Exposes Tor Browser Users to Remote Code Execution

A high-severity flaw in Firefox's SpiderMonkey JavaScript engine allows remote code execution simply by visiting a malicious page, directly impacting Tor Browser users on unpatched versions. Registered as CVE-2026-10702, the vulnerability stems from incorrect memory handling in the JIT compiler that leaves a dangling reference to freed memory, enabling arbitrary read and write primitives. Researchers demonstrated successful exploitation that can compromise the browser's content rendering process and facilitate user deanonymization or OS-level attacks. The same issue served as the initial stage in the IonStack exploit chain against ARM64 Android devices, where it was chained with CVE-2026-43499 in the Linux kernel to achieve root privileges. Mozilla addressed the issue in Firefox 151.0.3, and the Tor Project rolled out corresponding fixes in Tor Browser 15.0.19, which also incorporates the latest Firefox ESR updates.

Security NEXTVulnerabilities & Exploits

Google Releases Chrome Security Update Fixing 370 Vulnerabilities Including Seven Critical Issues

Google has issued a major security update for Chrome that addresses a total of 370 vulnerabilities across Windows, macOS, and Linux platforms. The update covers Chrome versions 151.0.7922.72 and 151.0.7922.71 and includes seven vulnerabilities rated Critical, the highest severity level. Among the critical flaws are multiple Use After Free issues affecting Compositing, Views, Skia, and Ozone components, plus input validation problems in Dawn and ANGLE graphics libraries and a race condition in the Updater component. In addition to the critical fixes, the release patches 71 High-severity vulnerabilities, 170 Medium-severity issues, and 122 Low-severity issues. The company plans a gradual rollout over the coming days and weeks. All listed CVEs from CVE-2026-17650 through CVE-2026-18019 have been resolved in this update.