CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
CVSS score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-303
Vendorsvmware
Affected products
| Vendors | Product | Versions |
|---|---|---|
| vmware | vcenter server | < 8.0 |
| vmware | telco cloud infrastructure | 3.0 |
| vmware | telco cloud platform | <= 5.2 |
| vmware | cloud foundation | - |
| vmware | vsphere foundation | - |
Related articles
VulnerabilitiesVMware patches critical flaws: VM escape and risk of total control of the virtual infrastructure
Broadcom patched critical VMware flaws in ESXi and vCenter. Updates fix severe VM escape and RCE flaws risking total virtual infrastructure control.
VulnerabilitiesVMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access
CVE-2026-59310 exploitation in VMware vCenter allows persistent access via cron jobs and reverse_ssh. Apply patches to mitigate.
This product uses the NVD API but is not endorsed or certified by the NVD.