Vulnerabilities & Exploits

vCenter Flaws Expose the Whole Virtual Estate

A flaw in vCenter is a control-plane problem, not a single-server problem. If an attacker reaches the management plane, they can try to take over the layer that governs ESXi hosts, virtual machines, and central administration.

Broadcom and national CERTs now give coordinated guidance for two critical vCenter issues: CVE-2026-59309, an authentication bypass, and CVE-2026-59310, a directory traversal flaw in the Syslog server that can lead to arbitrary code execution. Both affect unauthenticated attackers with network access, and there is still no known exploitation in the wild. Broadcom’s fixed versions are 8.0 U3k, 9.0.2.0100, and 9.1.0.0300, with related guidance also covering vSphere Foundation, Cloud Foundation, and Telco Cloud variants.

8 sources · Jul 30

CVE-2026-59310

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Aug 21

CVE-2026-59309

NVD KEV

Timeline

Sources

Vendor digest: VMware

Part of the PlainSec briefing for 2026-07-29

Every edition of this story: vCenter Flaws Expose the Whole Virtual Estate

More from today