Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-59309: VMware vCenter Authentication Bypass Risk

CVE-2026-59309 · published 2 months ago
Summary

VMware vCenter's authentication system has a weakness that could allow an attacker with network access to bypass security checks and access the system without a valid login. This could lead to unauthorized access to sensitive information and potential system compromise. To mitigate this risk, ensure VMware vCenter is properly configured and patched with the latest security updates.

What to do
  • Update vmware vcenter to version 9.1.0.0300 or later.
Affected software
VendorProductAffected versions
vmware cloud foundation 9.1.x.x
vmware vsphere foundation 9.1.x.x
vmware vcenter < 9.1.0.0300
vmware telco cloud infrastructure 3.0
vmware telco cloud platform 5.1.x
Original advisory text
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and ...
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published30 Jul 2026
Updated27 Sep 2026
First seen30 Jul 2026
Sources
CVE-2026-59309 · MITRE
Track software like this
Free during beta