TGViewer
zerodayalpha zerodayalpha @zerodaytraining · 1.5K subscribers
Post #222 855
VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).

Two attack vectors:

1. Remote attack on vCenter –
CVE-2026-59309: auth bypass via network access
CVE-2026-59310: directory traversal RCE

An exploit would allow control of entire ESXi infrastructure.

2. A VM-escapable set of two bugs –
CVE-2026-59310: vmxnet3 OOBW
CVE-2026-41703: core OOBR

These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.

Diffing and exploiting (1) is straightforward and should be patched promptly.
  • ❤ 4
More from @zerodaytraining
  1. Sep 15, 2026⚡️ 0-Day Alert: Chrome v8 RCE CVE-2026-87491: WasmGetOwnProperty builtin may invoke a gett…
  2. Sep 8, 2026⚡️ 0-Day Alert: Chrome v8 RCE exploited in the wild CVE-2026-85046: v8 array-builtin callb…
  3. Aug 29, 2026Browser Exploit Surface model + bug overlay CVE callouts: randomly picked exploitable bug…
  4. Aug 21, 2026Mastery container: Multi-Specialization Essentials A curated course of foundational webina…
  5. Aug 13, 2026⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow deployments have been under active exploitat…
  6. Aug 5, 2026"In an era where autonomous AI agents are increasingly being used for vulnerability huntin…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →