Skip to main content Skip to local navigation

VMware vCenter Server multiple vulnerabilities (CVE-2026-59309,CVE-2026-59310)

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed set of vulnerabilities (CVE-2026-59309 and CVE-2026-59310) affects VMware vCenter Server and may allow a remote attacker with network access to bypass authentication and execute arbitrary code on vulnerable systems.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service component of VMware vCenter Server. A remote attacker with network access to vCenter can exploit this flaw to bypass authentication controls and gain unauthorized access to the affected system.
CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog Server component. A remote attacker can leverage this flaw to access unauthorized files and potentially achieve arbitrary code execution on the vCenter Server.

Affected Versions:

  • VMware vCenter Server 8.0
  • VMware Cloud Foundation ( 9.0.x, 9.1.x)
  • VMware vSphere Foundation (9.0.x, 9.1.x)
  • VMware Telco Cloud Platform (3.0,4.x,5.0.x,5.1.x)
  • VMware Telco Cloud Infrastructure 3.0


Impact:

Successful exploitation may allow attackers to bypass authentication or execute arbitrary code on the affected server.

Resolution:
Upgrade to the following fixed versions or later:-

  • VMware Cloud Foundation/ VMware vSphere Foundation 9.1.0.0300.
  • VMware Cloud Foundation/ VMware vSphere Foundation 9.0.2.0100
  • VMware vCenter 8.0 U3k.


Reference:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html

https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/

 

UIT Information Security



Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web