CVE-2026-59309
vCenter authentication-bypass vulnerability
Description
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
In plain language
AI Act nowCVE-2026-59309 is a VMware vCenter login-bypass flaw that lets an attacker get full control from the network without credentials; a typical small business should treat any internet- or network-exposed vCenter as an urgent risk.
Unauthenticated authentication-bypass (CWE-303) in the VMware Directory Service component of VMware vCenter allows an attacker with network access to bypass login and gain unauthorized administrative/full system access.
What to do now
- Check whether you run VMware vCenter (and the related products: Cloud Foundation, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform) and determine your exact vCenter version.
- Check whether the VMware Directory Service is exposed to the network (especially from the internet) and whether it is reachable from outside your internal network.
- If you are on a vulnerable vCenter version, upgrade to one of the fixed releases: vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k.
- If you cannot upgrade immediately, restrict network access so the Directory Service is not reachable from untrusted networks, then confirm reachability is blocked.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Codeen·The Hacker News· Patch VMware Workstation privilege-escalation
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomwareen·The Hacker News· Exploited VMware vCenter Babuk
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Accessen·The Hacker News· Exploited VMware vCenter cloud
- 3rd August – Threat Intelligence Reporten-us·Check Point Research· Incident Minnesota Water Systems data-breach
- VMware fixes three critical flaws allowing auth bypass, VM escapesen-us·BleepingComputer· Patch vCenter auth-bypass
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)en·Rapid7 Blog· Patch vCenter Server cloud
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escapeen·The Hacker News· Patch ESXi cloud
- Critical VM Escape Vulnerability Patched in VMware ESXien-us·SecurityWeek· Patch ESXi cloud
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59309 and every CVE in our database. Create a free account — no credit card required.
Create Free Account