vCenter Flaws Expose the Whole Virtual Estate

A flaw in vCenter is a control-plane problem, not a single-server problem. If an attacker reaches the management plane, they can try to take over the layer that governs ESXi hosts, virtual machines, and central administration. Broadcom and national CERTs now give coordinated guidance for two critical vCenter issues: CVE-2026-59309, an authentication bypass, and CVE-2026-59310, a directory traversal flaw in the Syslog server that can lead to arbitrary code execution. Both affect unauthenticated attackers with network access, and there is still no known exploitation in the wild. Broadcom’s fixed versions are 8.0 U3k, 9.0.2.0100, and 9.1.0.0300, with related guidance also covering vSphere Foundation, Cloud Foundation, and Telco Cloud variants.

Part of the PlainSec briefing for 2026-07-30

Sources