Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-59309

VMware vCenter Server unauthenticated remote code execution

Unauthenticated attackers with network access to vCenter Server can achieve remote code execution. CVSS 9.8. Broadcom advisory VMSA-2026-0006 released July 29, 2026.

cat cve-2026-59309.json
Vendor
Broadcom (VMware)
Product
VMware vCenter Server
CVSS
9.8
EPSS (exploit probability)
0.7%
Status
patched
Published

CVE-2026-59309 is a CVSS 9.8 critical flaw in VMware vCenter Server, addressed in Broadcom security advisory VMSA-2026-0006 (July 29, 2026). An unauthenticated attacker with network access to a vulnerable vCenter Server instance can exploit this vulnerability to achieve remote code execution on the management host.

Because vCenter manages the full virtual estate — ESXi hosts, VMs, storage, and networking — remote code execution at this layer can translate to complete infrastructure access without requiring any credentials or existing foothold on the network.

Affected versions: Consult the Broadcom VMSA-2026-0006 advisory for affected version ranges across vCenter Server releases.

Fix: Broadcom has released patched vCenter Server builds. See the advisory for version-specific upgrade paths.

Priority: Patch immediately. No authentication required and no user interaction needed — any vCenter Server reachable over the network is exposed. See also CVE-2026-59310, the companion authentication bypass in the same advisory.