securityonline.info 7/29/2026, 11:51:15 AM · external

Critical VMware vCenter flaw lets hackers bypass authentication

Critical VMware vCenter flaw lets hackers bypass authentication
Developing story vulnerability 2 articles tracked
Critical VMware vCenter authentication bypass flaw patched (CVE-2026-59309)
CyberSIXT Evidence Panel
Primary Source support.broadcom.com
CISA KEV Not in KEV
Patch Patch Status Unknown

BROADCOM has released patches for critical vulnerabilities in VMware products, notably an authentication bypass in vCenter Server (CVE-2026-59309) which has a CVSS score of 9.8, allowing attackers unauthorized access. Other related vulnerabilities include directory traversal flaws and out-of-bounds write errors. The affected VMware products include ESX, vCenter, Workstation, and Fusion. Immediate updates are required, specifically to versions 9.1.0.0300, 9.0.2.0100, or 8.0 U3k.

The advisory emphasizes that patches are cumulative and that no workarounds exist for these critical issues. System administrators should prioritize these updates to safeguard their environments.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline