Vulnerabilities · 46 days ago
vCenter Flaws Expose the Whole Virtual Estate A flaw in vCenter is a control-plane problem, not a single-server problem. If an attacker reaches the management plane, they can try to take over the layer that governs ESXi hosts, virtual machines, and central administration.
Broadcom and national CERTs now give coordinated guidance for two critical vCenter issues: CVE-2026-59309 , an authentication bypass, and CVE-2026-59310 , a directory traversal flaw in the Syslog server that can lead to arbitrary code execution. Both affect unauthenticated attackers with network access, and there is still no known exploitation in the wild. Broadcom’s fixed versions are 8.0 U3k, 9.0.2.0100 , and 9.1.0.0300 , with related guidance also covering vSphere Foundation, Cloud Foundation, and Telco Cloud variants.
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Aug 21
CVE-2026-59309 NVD KEV
Timeline Sources 8 sources covering this story
BleepingComputer Jul 30
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
CSIRT Italia / ACN Jul 30
Vulnerabilità in prodotti VMware
Broadcom ha rilasciato aggiornamenti di sicurezza per risolvere alcune nuove vulnerabilità, di cui 3 con gravità “critica” e una con gravità “alta”, in vari prodotti della suite VMware.
Rapid7 Jul 30
Critical Vmware Vcenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution CVE-2026-59309 CVE-2026-59310
Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310.
INCIBE-CERT Jul 30
Múltiples vulnerabilidades en productos de VMware
VMware ha publicado 5 vulnerabilidades: 3 de severidad critica, 1 alta y 1 baja.
The Hacker News Jul 29
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom fixes two critical VMware vCenter flaws and a VMXNET3 ESX escape, with no evidence of exploitation in the wild.
NCSC-NL Advisories Jul 29
Kwetsbaarheden verholpen in VMware producten Revisies
VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309.
SecurityWeek Jul 29
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
Zero Day Initiative Advisories Jul 29
(Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability
(Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi.
Entities CVE-2026-59309 CVE-2026-59310 Vendor digest: VMware
Part of the PlainSec briefing for 2026-07-31
Editions Related stories
Vulnerabilities · 46 days ago
vCenter Flaws Expose the Whole Virtual Estate A flaw in vCenter is a control-plane problem, not a single-server problem. If an attacker reaches the management plane, they can try to take over the layer that governs ESXi hosts, virtual machines, and central administration.
Broadcom and national CERTs now give coordinated guidance for two critical vCenter issues: CVE-2026-59309 , an authentication bypass, and CVE-2026-59310 , a directory traversal flaw in the Syslog server that can lead to arbitrary code execution. Both affect unauthenticated attackers with network access, and there is still no known exploitation in the wild. Broadcom’s fixed versions are 8.0 U3k, 9.0.2.0100 , and 9.1.0.0300 , with related guidance also covering vSphere Foundation, Cloud Foundation, and Telco Cloud variants.
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Aug 21
CVE-2026-59309 NVD KEV
Timeline Sources 8 sources covering this story
BleepingComputer Jul 30
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
CSIRT Italia / ACN Jul 30
Vulnerabilità in prodotti VMware
Broadcom ha rilasciato aggiornamenti di sicurezza per risolvere alcune nuove vulnerabilità, di cui 3 con gravità “critica” e una con gravità “alta”, in vari prodotti della suite VMware.
Rapid7 Jul 30
Critical Vmware Vcenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution CVE-2026-59309 CVE-2026-59310
Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310.
INCIBE-CERT Jul 30
Múltiples vulnerabilidades en productos de VMware
VMware ha publicado 5 vulnerabilidades: 3 de severidad critica, 1 alta y 1 baja.
The Hacker News Jul 29
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom fixes two critical VMware vCenter flaws and a VMXNET3 ESX escape, with no evidence of exploitation in the wild.
NCSC-NL Advisories Jul 29
Kwetsbaarheden verholpen in VMware producten Revisies
VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309.
SecurityWeek Jul 29
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.
Zero Day Initiative Advisories Jul 29
(Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability
(Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability Vulnerability Details This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi.
Entities CVE-2026-59309 CVE-2026-59310 Vendor digest: VMware
Part of the PlainSec briefing for 2026-07-31
Editions Related stories