Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities

Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter fingerprinting activity. The activity includes requests to the /sdk/ endpoint using RetrieveServiceContent and exploration of the /websso single sign-on path. The requests do not prove compromise but show that attackers are identifying exposed systems before launching more direct attacks. The activity follows Broadcom’s VMSA-2026-0006 security advisory , released on July 29. The advisory covers five VMware flaws across vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products. Three bugs received critical ratings. The most urgent issue for vCenter administrators is CVE-2026-59309, an authentication bypass in VMware Directory Service, vmdir. It has a CVSS score of 9. 8.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310 . Both vulnerabilities carry CVSSv3. 1 base scores of 9. 8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical)

·Rapid7 Blog
Read →

You've reached the end of current stories for this search.