VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8
TL;DR
Broadcom has patched five flaws across VMware ESX, vCenter, Workstation, and Fusion. Two of them form a critical VMware vCenter vulnerability pair, each rated 9.8 CVSS. One lets an attacker bypass authentication; the other allows remote code execution. Broadcom reports no in-the-wild exploitation.VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass
Why it matters
vCenter runs the control plane for VMware environments. A single compromise can expose every managed host. So a 9.8-rated flaw here is a serious problem for data centers.
The advisory, VMSA-2026-0006, lists no workarounds for the critical bugs. Patching is the only fix. That raises the urgency for administrators, since vCenter has drawn repeated attacker interest over the years.
How the attacks work
CVE-2026-59309 sits in the VMware Directory Service. Broadcom states that an attacker “may exploit this issue to bypass authentication and gain unauthorized accVMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8ess.” Only network access to vCenter is required.
CVE-2026-59310 is a directory traversal flaw in the vCenter Syslog server. Here, an attacker with network access can run arbitrary code. Both bugs carry the maximum 9.8 score, and Atredis Partners reported them.
A guest-to-host escape
The third critical flaw affects ESX. CVE-2026-47876 is an out-of-bounds write in the VMXNET3 virtual network adapter, rated 9.3. Broadcom warns that an attacker with local admin rights on a VM “may exploit this issue to execute code on the host.”
In effect, this is a virtual machine escape. Non-VMXNET3 adapters are not affected. A STAR Labs researcher reported it through the Pwn2Own contest.
Two lower-severity issues
Two further bugs round out the VMware vCenter vulnerability advisory. CVE-2026-41703 is an out-of-bounds read in ESX, Workstation, and Fusion, rated up to 7.6. It can cause information disclosure or denial of service. CVE-2026-41709 is a low-severity logging gap, scored 2.7.
Affected versions
The critical vCenter flaws affect versions 9.1.x, 9.0.x, and 8.0, plus Cloud Foundation and Telco Cloud builds. The VMXNET3 bug hits the matching ESX releases. Workstation and Fusion 25H2 are affected only by the out-of-bounds read.
Patch and mitigation
Update now. For vCenter, Broadcom fixes land in 9.1.0.0300, 9.0.2.0100, and 8.0 U3k. For ESX, apply the ESXi builds listed in the response matrix.
No workarounds exist for these issues, so patching is the path. Review the full matrix in the official Broadcom advisory before you start. No public proof-of-concept has been confirmed at this time.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.