Critical severity9.8NVD Advisory· Published Jul 30, 2026· Updated Aug 25, 2026
CVE-2026-59309
CVE-2026-59309
Description
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
13- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeThe Hacker News · Sep 5, 2026
- VMware vCenter Attackers Drop JSP Webshell Disguised as Performance UpdateCyber Security News · Aug 18, 2026
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareThe Hacker News · Aug 17, 2026
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessThe Hacker News · Aug 12, 2026
- Hackers Actively Scanning to Exploit VMware VCenter VulnerabilitiesCyber Security News · Aug 11, 2026
- 3rd August – Threat Intelligence ReportCheck Point Research · Aug 3, 2026
- Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 StoriesCyber Security News · Aug 2, 2026
- VMware fixes three critical flaws allowing auth bypass, VM escapesBleepingComputer · Jul 30, 2026
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Rapid7 Blog · Jul 30, 2026
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeThe Hacker News · Jul 29, 2026
- Critical VM Escape Vulnerability Patched in VMware ESXiSecurityWeek · Jul 29, 2026
- Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the SystemCyber Security News · Jul 29, 2026