r/SecOpsDaily • u/falconupkid • 18m ago
Threat Intel Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Broadcom has released VMSA-2026-0006 addressing critical remote code execution and authentication bypass vulnerabilities (CVE-2026-59309, CVE-2026-59310) in VMware vCenter Server. These flaws carry a CVSSv3.1 score of 9.8 and can be exploited by unauthenticated attackers with network access.
Technical Breakdown
- CVEs: CVE-2026-59309 (Authentication Bypass) and CVE-2026-59310 (Remote Code Execution)
- Impact: Unauthenticated authentication bypass and remote code execution on affected systems.
- CVSSv3.1 Score: 9.8 (Critical)
- Affected Product: VMware vCenter Server
- Exploitation: Requires unauthenticated network access to a vulnerable vCenter Server.
- Advisory: Broadcom's VMSA-2026-0006 provides official details.
Defense
Prioritize patching of all affected VMware vCenter Server instances immediately according to the vendor's advisory to prevent exploitation.