Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
PatchvCenter ServerOur summary
Broadcom has issued a security update addressing two high-severity vulnerabilities in VMware vCenter Server—CVE-2026-59309 and CVE-2026-59310—that could allow unauthenticated attackers to bypass authentication or execute arbitrary code remotely. Both flaws have a CVSSv3.1 score of 9.8 and affect widely used vCenter versions. While no active exploitation has been observed yet, the lack of workarounds makes immediate patching crucial. Affected organizations are advised to apply the fixes detailed in VMSA-2026-0006 without delay.
Below is the opening; the full story is at Rapid7 Blog.
From Rapid7 Blog
Overview
On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.