Broadcom has issued patches for five vulnerabilities in its VMware products, including three deemed critical. The affected products encompass a range of VMware solutions, such as ESX, vCenter, and vSphere Foundation. Notably, CVE-2026-59309 poses a significant threat as it could allow malicious actors to bypass authentication in vCenter by exploiting the VMware Directory Service1. Another vulnerability, CVE-2026-47876, also poses a risk to the security of these systems. The disclosure of these vulnerabilities expands the attack surface, making it essential for organizations to prioritize patching based on their exposure and evidence of exploitation. This is particularly crucial for entities relying on VMware products, as the vulnerabilities could be leveraged by attackers to gain unauthorized access to sensitive systems. The patches address these vulnerabilities, mitigating the risk of exploitation, so what matters most to practitioners is promptly assessing their exposure and applying the necessary patches to prevent potential attacks.