VMware vCenter Server unauthenticated remote code execution
Unauthenticated attackers with network access to vCenter Server can achieve remote code execution. CVSS 9.8. Broadcom advisory VMSA-2026-0006 released July 29, 2026.
- Vendor
- Broadcom (VMware)
- Product
- VMware vCenter Server
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.7%
- Status
- patched
- Published
CVE-2026-59309 is a CVSS 9.8 critical flaw in VMware vCenter Server, addressed in Broadcom security advisory VMSA-2026-0006 (July 29, 2026). An unauthenticated attacker with network access to a vulnerable vCenter Server instance can exploit this vulnerability to achieve remote code execution on the management host.
Because vCenter manages the full virtual estate — ESXi hosts, VMs, storage, and networking — remote code execution at this layer can translate to complete infrastructure access without requiring any credentials or existing foothold on the network.
Affected versions: Consult the Broadcom VMSA-2026-0006 advisory for affected version ranges across vCenter Server releases.
Fix: Broadcom has released patched vCenter Server builds. See the advisory for version-specific upgrade paths.
Priority: Patch immediately. No authentication required and no user interaction needed — any vCenter Server reachable over the network is exposed. See also CVE-2026-59310, the companion authentication bypass in the same advisory.
