Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE
Overview
On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.
CVE | CVSSv3.1 | Description Summary |
|---|---|---|
CVE-2026-59309 | An authentication bypass vulnerability in the VMware Directory Service of vCenter that could allow a remote attacker to bypass authentication and gain unauthorized access to the vCenter management plane. | |
CVE-2026-59310 | A directory traversal vulnerability in the vCenter Syslog server that could allow an attacker with network access to execute arbitrary code. |
VMware vCenter Server provides centralized management for VMware vSphere environments, allowing administrators to manage ESXi hosts, virtual machines, resource allocation, availability, and other virtualization infrastructure from a central control plane. Compromise of vCenter can therefore provide an attacker with significant control over the virtualized environment and its associated workloads.
Both vulnerabilities are particularly significant because exploitation does not require prior authentication. However, an attacker must have network access to the affected vCenter services. Management interfaces such as vCenter are commonly restricted to internal or dedicated management networks, which can reduce exposure to internet-based attacks but does not mitigate the risk from an attacker who has already established access to an organization’s network.
At the time of publication, there is no known evidence of exploitation or scanning in the wild for either CVE-2026-59309 or CVE-2026-59310. There is also currently no known public proof-of-concept exploit code. However, vCenter Server has appeared on CISA’s KEV list ten times in the past for other vulnerabilities, so it is known that attackers target critical issues in this product. Customers running affected VMWare products are urged to patch on an urgent basis before exploitation in-the-wild occurs.
Mitigation guidance
Organizations running VMware vCenter Server should prioritize applying the updates identified by Broadcom in VMSA-2026-0006 on an urgent basis. Broadcom states that there are no workarounds for CVE-2026-59309 or CVE-2026-59310, making vendor-provided updates the primary remediation.
VMware Product | Component | Version | Running On | Fixed Version |
VMware Cloud Foundation, VMware vSphere Foundation | vCenter | 9.1.x.x | Any | |
VMware Cloud Foundation, VMware vSphere Foundation | vCenter | 9.0.x.x | Any | |
VMware vCenter | N/A | 8.0 | Any | |
VMware Cloud Foundation | vCenter | 5.x | Any | Async patch to 8.0 U3k |
VMware Telco Cloud Platform | vCenter | 3.0, 4.x, 5.0.x, 5.1.x | Any | Refer to KB449886 |
VMware Telco Cloud Infrastructure | vCenter | 3.0 | Any | Refer to KB449886 |
For the latest mitigation guidance, please refer to the vendor advisory.
Rapid7 customers
Exposure Command, InsightVM, and Nexpose
Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-59309 and CVE-2026-59310 on VMware vCenter Server, Cloud Foundation, and vSphere Foundation products with unauthenticated vulnerability checks expected to be available in the July 30 content release.
Updates
July 30, 2026: Initial publication.
- July 30, 2026: Updated customers section to reflect availability of vulnerability checks.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.