Broadcom has patched five vulnerabilities across its VMware lineup, and anyone running vSphere in production should look at this today, not after the weekend. Next is CVE-2026-47876, an out-of-bounds write bug in ESXi’s VMXNET3 virtual network adapter. At least the damage stays contained to that specific adapter; other virtual network configurations aren’t affected. Broadcom rated the fourth issue, CVE-2026-41703, as high instead of critical, though it actually spans several vulnerabilities across ESX, vCenter, Workstation, and Fusion. Altogether, the affected products cover a wide slice of Broadcom’s portfolio: ESX, vCenter, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and both Telco Cloud products.