July 30, 2026
- Broadcom patched critical VMware flaws including a vCenter authentication bypass (CVE-2026-59309), a Directory-Service/Syslog directory traversal (CVE-2026-59310), and an ESXi VM-escape enabling code execution on the host. No exploitation reported yet, but escape-class bugs warrant priority. The Hacker News, SecurityWeek · Vulnerabilities & Exploits
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius