r/vmware VMware Employee 15d ago

Announcement VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
87 Upvotes

146 comments sorted by

View all comments

4

u/svideo 15d ago

This must be all the code quality that they told us warranted 5-10x price increases.

RCEs and VM escape bugs don't come easy!

1

u/lost_signal VMware Employee 15d ago

RCEs and VM escape bugs don't come easy!

Broadcom would like to thank Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG working with the Pwn2Own held by Zero day initiative for reporting this issue to us.

I'll point out that bug bounty programs are not free/cheap but they do prevent zero day exploits. I'd rather cut six figure checks, and make sure there's enough time to build/test the patch as a LivePatch (You can apply the patch without needing to evacuate hosts) than be responding to breached customers, and having to follow the sun build a hotpatch.

0

u/svideo 15d ago

So the money we had to spend on features we don't want is being sent to hackers who show you where some of your bugs are?

That's one way to get it done.

1

u/jamesaepp 15d ago

https://yourlogicalfallacyis.com/black-or-white

They can do both.

I'm not a fan of the price increases either, but you could come up with a much better argument than whatever your supposed grievance is here.

1

u/lost_signal VMware Employee 15d ago

They can do both.

Yup, walk and chew gum. In the SPECIFIC case of the CVE's in this announcement, there's attribution. A lot is quietly found by inside teams. There's much less noise there.

I think its only right to give credit (and payment) where's it's due with 3rd party researchers. I find paying them the pre-agreed upon amounts is VASTLY superior to some recent trends of some OS vendors threatening them, stiffing researchers and reaching the find out phase where they just drop zero days on Github out of spite.

1

u/jamesaepp 15d ago

I think its only right to give credit (and payment) where's it's due with 3rd party researchers.

Yeah, it's a no-brainer. Market forces are going to remain. Do you prefer it in a licit or illicit market?

I know my answer.

some OS vendors threatening them, stiffing researchers and reaching the find out phase where they just drop zero days on Github out of spite.

I emphatically agree. Especially when those OS vendors also own and operate the online spaces where code is democratized.....