CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◆ Security Tools & Reviews Jul 30, 2026

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 Archived Jul 30, 2026 ✓ Full text saved

Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (

Full text archived locally
✦ AI Summary · Claude Sonnet


    OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could allow a remote attacker to bypass authentication and gain unauthorized access to the vCenter management plane.CVE-2026-593109.8 (Critical)A directory traversal vulnerability in the vCenter Syslog server that could allow an attacker with network access to execute arbitrary code.VMware vCenter Server provides centralized management for VMware vSphere environments, allowing administrators to manage ESXi hosts, virtual machines, resource allocation, availability, and other virtualization infrastructure from a central control plane. Compromise of vCenter can therefore provide an attacker with significant control over the virtualized environment and its associated workloads.Both vulnerabilities are particularly significant because exploitation does not require prior authentication. However, an attacker must have network access to the affected vCenter services. Management interfaces such as vCenter are commonly restricted to internal or dedicated management networks, which can reduce exposure to internet-based attacks but does not mitigate the risk from an attacker who has already established access to an organization’s network.At the time of publication, there is no known evidence of exploitation or scanning in the wild for either CVE-2026-59309 or CVE-2026-59310. There is also currently no known public proof-of-concept exploit code. However, vCenter Server has appeared on CISA’s KEV list ten times in the past for other vulnerabilities, so it is known that attackers target critical issues in this product. Customers running affected VMWare products are urged to patch on an urgent basis before exploitation in-the-wild occurs.Mitigation guidanceOrganizations running VMware vCenter Server should prioritize applying the updates identified by Broadcom in VMSA-2026-0006 on an urgent basis. Broadcom states that there are no workarounds for CVE-2026-59309 or CVE-2026-59310, making vendor-provided updates the primary remediation.VMware ProductComponentVersionRunning OnFixed VersionVMware Cloud Foundation,VMware vSphere FoundationvCenter9.1.x.xAny9.1.0.0300VMware Cloud Foundation,VMware vSphere FoundationvCenter9.0.x.xAny9.0.2.0100VMware vCenterN/A8.0Any8.0 U3kVMware Cloud Foundation vCenter5.xAnyAsync patch to 8.0 U3kVMware Telco Cloud PlatformvCenter3.0, 4.x, 5.0.x, 5.1.xAnyRefer to KB449886VMware Telco Cloud Infrastructure vCenter3.0AnyRefer to KB449886For the latest mitigation guidance, please refer to the vendor advisory.Rapid7 customersExposure Command, InsightVM, and NexposeExposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-59309 and CVE-2026-59310 on VMware vCenter Server, Cloud Foundation, and vSphere Foundation products with unauthenticated vulnerability checks expected to be available in the July 30 content release.UpdatesJuly 30, 2026: Initial publication.Article TagsEmergent Threat ResponseLabsRapid7Author PostsRelated blog postsVulnerabilities and ExploitsCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityRapid7Vulnerabilities and ExploitsCVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildRapid7Vulnerabilities and ExploitsCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreRapid7 LabsVulnerabilities and ExploitsCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the WildRapid7See all posts
    💬 Team Notes
    Article Info
    Source
    Rapid7
    Category
    ◆ Security Tools & Reviews
    Published
    Jul 30, 2026
    Archived
    Jul 30, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗