VMware vCenter Server multiple vulnerabilities (CVE-2026-59309,CVE-2026-59310)
Posted on
July 29, 2026
Information Security Advisory
A recently disclosed set of vulnerabilities (CVE-2026-59309 and CVE-2026-59310) affects VMware vCenter Server and may allow a remote attacker with network access to bypass authentication and execute arbitrary code on vulnerable systems. Severity level: CVSS Score: 9.8/Critical. Description: CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service component of VMware vCenter Server. A remote attacker with network access to vCenter can exploit this flaw to bypass authentication controls and gain unauthorized access to the affected system. CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog Server component. A remote attacker can leverage this flaw to access unauthorized files and potentially achieve arbitrary code execution on the vCenter Server. Affected Versions:
VMware vCenter Server 8.0
VMware Cloud Foundation ( 9.0.x, 9.1.x)
VMware vSphere Foundation (9.0.x, 9.1.x)
VMware Telco Cloud Platform (3.0,4.x,5.0.x,5.1.x)
VMware Telco Cloud Infrastructure 3.0
Impact: Successful exploitation may allow attackers to bypass authentication or execute arbitrary code on the affected server. Resolution: Upgrade to the following fixed versions or later:-
VMware Cloud Foundation/ VMware vSphere Foundation 9.1.0.0300.
VMware Cloud Foundation/ VMware vSphere Foundation 9.0.2.0100