Vulnerabilities & PatchesEmerging1 src
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Overview
On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310 . Both vulnerabilities carry CVSSv3. 1 base scores of 9.
8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.
CVE
CVSSv3.1
Description Summary
CVE-2026-59309
9.8 (Critical)
VmwareCVE-2026-59309CVE-2026-59310