Skip to content
feed: live
>_ 0dayNews
vmware
● Breaking

vCenter Auth Bypass CVE-2026-59310 Now Exploited

CVE-2026-59310 exploitation confirmed in VMware vCenter Server. CVSS 9.8. Patches out since July 29 — unpatched instances need isolation now.

vCenter Auth Bypass CVE-2026-59310 Now Exploited
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
airgap airgap · Published · 1 min read

Active exploitation confirmed. CVE-2026-59310 — the CVSS 9.8 authentication bypass in Broadcom VMware vCenter Server — is being leveraged by threat actors against live infrastructure, per threat intelligence published by QUIRSO via The Hacker News.

What Was Disclosed

CVE-2026-59310 is an unauthenticated authentication bypass in VMware vCenter Server, fixed in Broadcom advisory VMSA-2026-0006 on July 29, 2026. An attacker with network access — not internet-exposed, just network-reachable — can bypass vCenter’s authentication layer without credentials. When chained with CVE-2026-59309 (unauthenticated remote code execution, same advisory), the result is complete unauthenticated takeover of the vCenter management plane.

Rapid7’s early technical review confirmed the severity and attack vector at disclosure time.

What Just Changed

Exploitation has moved from theoretical to confirmed. The patch dropped July 29, 2026 — 14 days ago. Threat actors are now operating in the patch gap.

Why This Is a Full-Estate Event

vCenter manages the hypervisor layer: ESXi hosts, all virtual machines, storage, and network fabric for everything those VMs touch. There is no containment story once the management plane falls. Blast radius is the entire virtual estate under that vCenter instance. Unconfirmed — treat accordingly — that attribution and persistence mechanisms are still being characterized by QUIRSO.

Actions, Ordered by Impact

  1. Patch. VMSA-2026-0006. Available since July 29. No reason to be unpatched at this point.
  2. Network-isolate vCenter. Management interfaces belong on dedicated management networks, not reachable from guest VLANs, contractor segments, or the general corporate network. A network-adjacent attacker is sufficient to trigger this flaw.
  3. Audit authentication logs from July 29 onward. Look for anomalous session creation, unexpected access patterns, or unauthenticated access events against the vCenter management interface.
  4. Assume managed ESXi hosts are in scope if you cannot confirm your vCenter instance was never exposed to an untrusted network segment since July 29.

Current CISA KEV status: not yet listed. The exploitation confirmation significantly increases KEV addition likelihood — monitor the KEV tracker.

Previously covered: Broadcom VMware vCenter and ESXi Critical Patch Advisory, July 2026.

Related CVEs
  • [ CRITICAL ] CVE-2026-59310 VMware vCenter Server unauthenticated authentication bypass

Found this useful? Share it.