CVE Tools

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 BlogBy Rapid72 min read

PatchvCenter Server

Our summary

Broadcom has issued a security update addressing two high-severity vulnerabilities in VMware vCenter Server—CVE-2026-59309 and CVE-2026-59310—that could allow unauthenticated attackers to bypass authentication or execute arbitrary code remotely. Both flaws have a CVSSv3.1 score of 9.8 and affect widely used vCenter versions. While no active exploitation has been observed yet, the lack of workarounds makes immediate patching crucial. Affected organizations are advised to apply the fixes detailed in VMSA-2026-0006 without delay.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store