VMware CVSS 9.8 vCenter auth bypass and CVSS 9.3 ESXi VM escape: no workarounds, Broadcom says treat as emergency change      Minnesota water OT attack: 30-plus community water systems disrupted over the weekend, federal investigation underway      Firefox CVE-2026-10702: JIT compiler flaw executes code inside the renderer on a page visit, no click or interaction required      VMware CVSS 9.8 vCenter auth bypass and CVSS 9.3 ESXi VM escape: no workarounds, Broadcom says treat as emergency change      Minnesota water OT attack: 30-plus community water systems disrupted over the weekend, federal investigation underway      Firefox CVE-2026-10702: JIT compiler flaw executes code inside the renderer on a page visit, no click or interaction required     
CyberSipTM
Intelligence without the noise
Issue No. 97
July 30, 2026
3 items · past 24h
<5 min read
Today's picture

Broadcom published emergency patches for VMware vCenter Server and ESXi yesterday covering a CVSS 9.8 unauthenticated authentication bypass in vCenter, a CVSS 9.3 VM escape in ESXi through the VMXNET3 adapter, and a separate unauthenticated code execution path in vCenter, with no workarounds available for any of the three critical flaws. A coordinated cyberattack hit operational technology systems at more than 30 Minnesota community water utilities over the weekend, knocking automated controls offline, sending one plant entirely offline, and triggering a statewide response involving CISA, the FBI, and the EPA with attribution still under investigation. And Mozilla pushed Firefox 151.0.3 to patch CVE-2026-10702, a just-in-time compiler flaw that lets an attacker execute arbitrary code inside the browser renderer by loading a malicious page, no click or credential required, which was also used to compromise Tor Browser.

Today's intelligence
3 items
01 CriticalVMwareNo Workaround
Broadcom patches a CVSS 9.8 vCenter auth bypass and a CVSS 9.3 ESXi VM escape with no workarounds and emergency change guidance
Three critical vulnerabilities in one advisory, none with a workaround. vCenter is the management plane for every ESXi host in a VMware environment. An unauthenticated attacker who bypasses vCenter authentication has administrative reach over all managed hypervisors without needing to exploit the VM escape separately.
AdvisoryVMSA-2026-0006
Critical CVEsCVE-2026-59309
CVE-2026-59310
CVE-2026-47876
CVSS scores9.8, 9.8, 9.3
WorkaroundNone for any
critical flaw
ExploitedNot confirmed
in wild yet
Broadcom published VMSA-2026-0006 on July 29 addressing five vulnerabilities across VMware ESXi, vCenter, Workstation, and Fusion. Three carry critical severity ratings. CVE-2026-59309, CVSS 9.8, is an authentication bypass in the VMware Directory Service used by vCenter Server. An attacker with network access to vCenter can bypass authentication and gain unauthorized access to the management platform with no credentials, no prior session, and no user interaction required. CVE-2026-59310, also CVSS 9.8, is a directory traversal vulnerability in vCenter that allows a separate unauthenticated code execution path for attackers with network access. CVE-2026-47876, CVSS 9.3, is an out-of-bounds write in ESXi's implementation of the VMXNET3 virtual network adapter. An attacker with local administrative privileges on a guest virtual machine can exploit it to execute arbitrary code on the underlying ESXi host, constituting a full VM escape. Broadcom explicitly states that there are no workarounds for CVE-2026-59309 or CVE-2026-59310 and recommends treating remediation as an emergency change. Fixed versions are vCenter Server 9.1.0.0300, 9.0.2.0100, and 8.0 U3k, and ESXi versions ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, and ESXi 8.0 U3k. VMware Cloud Foundation 5.x customers must follow the asynchronous patching process. No exploitation has been confirmed in the wild as of today, but vCenter has appeared on CISA KEV ten times previously, establishing a clear pattern of attacker interest in this product category. A fifth vulnerability in the advisory, CVE-2026-41709, allows an ESXi administrator to conduct certain operations without those actions being logged, rated low severity.
vCenter Server is the single administrative plane through which VMware environments are managed. Every ESXi host, virtual machine, storage system, and network configuration in a virtualized environment is reachable through vCenter. An unauthenticated attacker who bypasses vCenter authentication through CVE-2026-59309 obtains administrative reach over the entire virtualized infrastructure without needing to separately exploit the VM escape. The two flaws are not additive. CVE-2026-59309 alone can give an external attacker administrative control of the hypervisor layer supporting every workload in the environment.
CVE-2026-47876 requires an attacker to already have local administrative privileges on a guest VM, which is a meaningful precondition. In practice that precondition is frequently met in shared hosting environments, cloud provider infrastructure, and any environment where multiple tenants or teams have administrator access to separate virtual machines on the same ESXi host. In those environments the VM escape is a path from one customer or team's administrative access to the host hypervisor underlying all other guests. Broadcom specifies that only VMs using the VMXNET3 virtual network adapter are affected. VMs using a different adapter type are not in scope for this specific flaw.
  • Apply VMSA-2026-0006 patches as an emergency change. Priority order: vCenter first to close the unauthenticated access path, then ESXi to close the VM escape. Use the Broadcom response matrix for the correct fixed version for each product branch. VMware Cloud Foundation customers must use the asynchronous patching process.
  • Restrict network access to vCenter management interfaces to trusted administrative networks. While the patch is the only full mitigation for CVE-2026-59309, limiting which network segments can reach vCenter reduces the exposure surface until the patch is applied.
  • For the ESXi VM escape, identify VMs using VMXNET3 adapters and assess which have tenants or teams with local administrative access who should not have host-level reach. Migrating high-risk VMs to a different adapter type removes the specific precondition for CVE-2026-47876.
No workarounds. No exploitation confirmed yet. vCenter has been on CISA KEV ten times before. Broadcom's own guidance says treat this as an emergency change, not a scheduled update. Patch vCenter before this week ends.
02 HighWater OTMinnesota
A coordinated cyberattack disabled automated controls at more than 30 Minnesota water utilities over the weekend, sending one plant entirely offline
The attack hit operational technology, not IT systems, across utilities of very different sizes simultaneously. One plant went fully offline. Three others lost automated control but maintained manual operations. CISA, the FBI, and the EPA are all involved. Attribution is under investigation.
Attack datesJuly 26–27, 2026
Utilities hit30-plus community
water systems
ImpactOT controls disabled
one plant offline
AttributionUnder investigation
no actor confirmed
Between Sunday July 26 and Monday July 27, attackers hit operational technology systems at more than 30 Minnesota community water and wastewater utilities in what Minnesota IT Services described as a coordinated cyberattack. Four cities publicly confirmed the incident. In Braham, population approximately 1,700, the water plant went entirely offline after computerized operating controls were disrupted. Crews restored operations within roughly two hours. Plymouth, population approximately 80,000, reported cellular communication failures at two water towers and multiple wastewater lift stations and disconnected affected cellular-connected equipment to halt the spread. South St. Paul and Maple Plain maintained water service after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response. By July 28, Minnesota IT Services confirmed the total affected count exceeded 30 communities. Minnesota officials described the attack as sharing characteristics with other coordinated cyberattacks on critical infrastructure that federal partners have observed. No specific access method, vulnerability, or industrial control system family has been publicly identified as the attack vector. CISA, the FBI, the EPA, the Minnesota Department of Public Safety, the Minnesota Department of Health, and the Minnesota Pollution Control Agency are all participating in the investigation and response. Water quality was not affected at any reported utility, and no communities have been asked to change their water use as of today.
A coordinated attack reaching more than 30 utilities simultaneously is not an opportunistic scan that happened to land on multiple targets. It reflects a deliberate operation against water sector operational technology at scale, in a single geographic region, over a two-day window. The EPA's own 2024 audit of 1,000 water systems found 97 with critical or high-risk vulnerabilities, and more than 70 percent of water systems failing to comply with risk assessment requirements under a 2018 law. The sector's security posture is distributed, under-resourced, and difficult to improve quickly. The Minnesota incident demonstrates what a coordinated attack on that posture looks like in practice.
The same week as the Minnesota attack, hacker group Hanzala separately claimed attacks on water utility systems in several California cities including Bakersfield, Chico, Salinas, and Stockton. Minnesota IT Services noted that the attack's timeline, access methods, and targeted infrastructure share characteristics with coordinated incidents federal partners have observed. US water utilities have previously been targeted by Iranian-affiliated actors, including the CyberAv3ngers group associated with Iran's Islamic Revolutionary Guard Corps, which has targeted internet-facing programmable logic controllers at water utilities. CISA's advisory AA26-097A, updated July 22, specifically expanded its documented scope of Iranian-affiliated PLC exploitation to include Schneider Electric and Siemens devices and added detection guidance for manipulation of reusable code in PLC programs.
  • Water and wastewater utilities should review CISA Advisory AA26-097A and CISA's CI Fortify guidance published this week for sector-specific defensive steps including isolating internet-facing OT systems, restricting controller access to authorized systems, and logging cellular modem connections to field equipment.
  • Validate backups of PLC project files before restoration and inspect running project files for unauthorized changes. CISA's AA26-097A specifically documented project file exfiltration in Iranian-affiliated campaigns as a new observed behavior. A restored project file from backup should be verified clean rather than assumed so.
  • Utilities still operating internet-exposed PLCs or human-machine interfaces without network isolation should treat the Minnesota incident as a direct operational risk signal and prioritize network segmentation for field control systems above other pending security projects.
More than 30 water utilities, two days, coordinated. The attack hit operational technology directly and knocked one plant offline. No actor has been confirmed. The EPA found that more than 70 percent of water systems were not meeting their own risk assessment obligations. The Minnesota incident is what the gap between that finding and reality looks like.
03 HighFirefoxTor Browser
Firefox patches a no-click JIT flaw that runs attacker code in the browser renderer from a malicious page visit, also used against Tor Browser
CVE-2026-10702 is a use-after-free in Firefox's JIT compiler. Visiting a malicious page triggers code execution inside the renderer process. No credentials, no prompt, no installed extension. Mozilla rated it High and shipped the emergency patch in Firefox 151.0.3. The same flaw was confirmed used against Tor Browser.
CVECVE-2026-10702
SeverityHigh
Fixed inFirefox 151.0.3
Firefox ESR 128.23
Firefox ESR 115.36
Tor BrowserAlso exploited
patch available
Mozilla shipped Firefox 151.0.3 on July 28 to patch CVE-2026-10702, a use-after-free vulnerability in the Firefox just-in-time JavaScript compiler discovered and reported by Eten Zou, CEO of Nebula Security. The flaw allows arbitrary code execution inside the browser's renderer process when a user visits a page serving a crafted exploit. No user settings are required, no click is needed beyond the initial navigation, and no browser extensions are involved. The renderer process is sandboxed, meaning code execution stays within the renderer without automatically escaping to the operating system. However, renderer-level code execution is the standard precursor to sandbox escape chains in browser exploitation: the attacker controls the renderer's memory and can attempt to reach the OS through a subsequent privilege escalation. Nebula Security confirmed the same flaw was used to compromise Tor Browser, which is based on Firefox ESR. Tor Browser users are at elevated risk because the anonymity guarantees of Tor depend on the browser not leaking information or executing attacker code, and a renderer compromise can be used to fingerprint or deanonymize a user even without a full OS-level escape. Firefox ESR 128.23 and 115.36 are also patched. Mozilla confirmed in-the-wild exploitation before the patch was published. Chrome and Safari users are not affected by this specific flaw.
Browser JIT compiler vulnerabilities that fire on page load are among the most operationally dangerous class of web-based flaw because they eliminate the user action requirement that most security training focuses on. Users are trained not to click suspicious links or open unexpected attachments. A JIT flaw that fires on page load is triggered by normal browsing behavior, including arriving at a legitimate site that has been compromised. The Tor Browser targeting is also a specific signal: Tor is used by journalists, activists, and others who are specifically trying to avoid tracking. A renderer exploit against Tor Browser is worth more to certain actors than an equivalent exploit against a mainstream browser because the victims are specifically trying to be anonymous.
Firefox updates automatically on most desktop configurations, but the update requires a restart to take effect. Users on delayed restart cycles who have Firefox open continuously, which is common on workstations, may be running a version they believe is current but have not yet restarted to apply. The version check to confirm patch status is Firefox menu, Help, About Firefox, which will show the current applied version and trigger an update if one is pending. Enterprise deployments with managed Firefox installs should verify the update has been pushed and that browser restarts have occurred, not just that the update was made available.
  • Confirm Firefox is running version 151.0.3 or later on all endpoints. Check via Help, About Firefox on individual machines. For enterprise deployments, verify through browser management tooling that the update has applied and that browsers have been restarted, not just that the update package was delivered.
  • Tor Browser users should update immediately through the Tor Browser update mechanism. Unpatched Tor Browser installations have a confirmed renderer-level code execution path that can be used for deanonymization regardless of Tor network-layer protections.
Visit a page, run attacker code in the browser. No click beyond loading the URL. Confirmed exploited before the patch shipped. Firefox auto-updates, but auto-update requires a restart to take effect. If Firefox has been open since before the patch, it needs a restart to be protected. Restart it now.
Cross-source standouts
01
VMware vCenter and the Arista VeloCloud deadline from yesterday: two management planes for two different infrastructure types, both under pressure this week
Yesterday's issue covered the Arista VeloCloud Orchestrator CVSS 10.0 zero-day with a federal deadline of today. Today's issue covers VMware vCenter CVSS 9.8 with no workaround and an emergency-change recommendation. Both are management plane vulnerabilities: VeloCloud Orchestrator manages the SD-WAN that connects branches and datacenters; vCenter manages the hypervisors that run the workloads at those locations. Compromising either gives an attacker administrative reach over the infrastructure that sits below it. vCenter in a VMware environment is not a server that administrators log into for routine tasks. It is the system through which every other server is configured, started, stopped, and monitored. An unauthenticated attacker bypassing vCenter authentication through CVE-2026-59309 obtains control of the entire virtualized environment, not a single host. The pairing of VeloCloud yesterday and vCenter today puts two of the most consequential management plane targets in enterprise infrastructure under simultaneous patch pressure. Both have critical unmitigated flaws. Neither has a workaround. Patch both this week.
02
The Minnesota water attack and the broader water sector security gap that the EPA audit quantified two years ago
The EPA's Office of Inspector General audit in 2024 found that more than 70 percent of water systems were failing to comply with a 2018 statutory requirement to develop or update risk assessments and emergency response plans. An audit of 1,000 systems serving 193 million people found 97 with critical or high-risk vulnerabilities. Those numbers describe a sector where the majority of regulated utilities had not completed the baseline security documentation required by law, not a sector where sophisticated defenses failed against a capable adversary. The Minnesota attack hit more than 30 systems simultaneously over two days. The commonality across those 30-plus systems, whether in vendor, access method, or vulnerability, is not yet public. What is public is that CISA's own advisory AA26-097A, updated a week before the Minnesota attack, documented Iranian-affiliated actors targeting internet-facing PLCs at water utilities and expanded the documented scope to include Schneider Electric and Siemens devices. Water sector OT security has been a documented national priority for years. The Minnesota incident is a direct operational demonstration that the gap between the documented risk and the actual defensive posture of small community utilities remains wide and consequential.
Still watching
Days 2–5
Certighost CVE-2026-54121 (Issue 96 · AD CS domain takeover) — working public PoC since July 24. Any domain user can obtain a DC certificate and run DCSync to extract krbtgt. Apply July 14 Patch Tuesday to all Enterprise CA servers. Interim mitigation: certutil -setreg policy\EditFlags -EDITF_ENABLECHASECLIENTDC and restart Certificate Services.
Day 2
TeamCity CVE-2026-63077 (Issue 95 · CVSS 9.8, all on-prem versions) — unauthenticated RCE via agent polling. Prior TeamCity CVEs were exploited within days of disclosure. Upgrade to 2025.11.7 or 2026.1.3. Install the patch plugin as a bridge if immediate upgrade is not possible.
Day 3
SharePoint machine key theft CVE-2026-50522 (Issue 92 · CISA KEV July 22) — confirmed exploited to steal IIS machine keys enabling permanent token-forging. Patch all five July SharePoint CVEs. Rotate IIS machine keys. Keys stolen before patching remain valid until explicitly rotated.
Day 7+
LegacyHive (Issue 88 · Nightmare Eclipse, no patch) — Windows User Profile Service privilege escalation, working proof of concept on fully patched July systems. No CVE, no fix. Now at Day 13. Three prior disclosures in this series were exploited before patches arrived.
Day 7+