Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-59310

VMware vCenter Server unauthenticated authentication bypass

Unauthenticated network-adjacent attackers can bypass authentication in VMware vCenter Server. CVSS 9.8. Part of Broadcom advisory VMSA-2026-0006, July 29, 2026.

cat cve-2026-59310.json
Vendor
Broadcom (VMware)
Product
VMware vCenter Server
CVSS
9.8
EPSS (exploit probability)
1.1%
Status
exploited-in-wild
Published

CVE-2026-59310 is a CVSS 9.8 critical authentication bypass in VMware vCenter Server, patched in Broadcom security advisory VMSA-2026-0006 (July 29, 2026). An unauthenticated attacker with network access to a vulnerable vCenter Server can bypass its authentication controls entirely — no credentials required.

An authentication bypass at the vCenter level means an attacker on the same network segment can gain unauthorized access to the management plane that governs the entire virtual infrastructure: compute hosts, virtual machines, storage, and networking fabric.

Affected versions: See Broadcom’s VMSA-2026-0006 advisory for the specific affected and fixed release ranges.

Fix: Upgrade to the patched vCenter Server releases listed in VMSA-2026-0006.

Priority: Patch this week. Paired with CVE-2026-59309 (unauthenticated RCE), the two flaws in the same advisory represent a complete unauthenticated takeover path for vCenter-managed infrastructure.