Friday, September 11, 2026

Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code

Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter authentication or execute arbitrary code.

These vulnerabilities, outlined in advisory VMSA-2026-0006, affect a range of products including vCenter, ESX, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, and selected Telco Cloud products.

The advisory, published on July 29, 2026, covers five vulnerabilities with CVSS v3 scores ranging from 2.7 to 9.8. Organizations should prioritize remediation because no workarounds are available for the two critical issues related to vCenter.

Critical VMware vCenter Flaws

The most severe vulnerability is CVE-2026-59309, which is an authentication bypass in the VMware Directory Service. A remote, unauthenticated attacker with network access to a vulnerable vCenter Server can bypass authentication controls and gain unauthorized access to the management platform.

Since vCenter centrally manages ESXi hosts, virtual machines, permissions, templates, and infrastructure workflows, a compromise could provide an attacker with a highly valuable foothold in a virtualized environment. Organizations should treat internet-exposed or poorly segmented vCenter deployments as urgent patching priorities.

The second critical vulnerability is CVE-2026-59310, a directory traversal flaw in the vCenter Syslog server. Broadcom indicates that an attacker with network access may exploit this flaw to execute arbitrary code, posing a significant risk of remote code execution on the vCenter appliance.

Both of these vulnerabilities carry a maximum CVSS v3 score of 9.8 and require no privileges or user interaction, according to their published CVSS vectors.

Vulnerabilities Addressed

  • CVE-2026-59309 – Critical, CVSS 9.8: Authentication bypass in VMware Directory Service affecting vCenter. A network-based attacker may bypass authentication and gain unauthorized system access.
  • CVE-2026-59310 – Critical, CVSS 9.8: Directory traversal in the vCenter Syslog server. A remote attacker with network access may execute arbitrary code.
  • CVE-2026-47876 – Critical, CVSS 9.3: Out-of-bounds write in the VMXNET3 virtual network adapter in VMware ESX. An attacker with local administrator privileges in a VM using VMXNET3 could execute code on the ESX host, effectively enabling a VM escape scenario. Non-VMXNET3 adapters are not affected.
  • CVE-2026-41703 – Important, CVSS 7.6: Out-of-bounds read affecting ESX, Workstation, and Fusion. An attacker with VM deployment privileges could potentially disclose information or cause a host-process denial-of-service; on Workstation and Fusion, the impact is limited to information disclosure.
  • CVE-2026-41709 – Low severity, CVSS 2.7: Insufficient logging in ESXi. A malicious administrator may perform certain operations without those actions being properly recorded in logs.

Patching Guidance

Broadcom advises organizations to apply the fixed versions listed in the VMSA-2026-0006 response matrix:

  • vCenter fixes include version 9.1.0.0300 for 9.1 deployments, 9.0.2.0100 for 9.0 deployments, and vCenter Server 8.0 U3k for version 8.0.
  • For ESX, organizations should deploy ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, or ESXi 8.0 U3k as applicable. VMware Cloud Foundation 5.x users must use the asynchronous patching process, while Telco Cloud customers should follow Broadcom KB449886.

Security teams should also restrict vCenter management interfaces to dedicated administrative networks, review privileged vCenter and ESXi accounts, and monitor for unusual authentication activity, new administrator accounts, configuration changes, or unexpected VMXNET3-related host events.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News