In a nutshell: CVE-2026-59309 enables an authentication bypass in VMware vCenter with critical severity rating (CVSS 9.8).
Broadcom has released security updates for multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion, including three flaws rated as critical. The first critical vulnerability, CVE-2026-59309 with CVSS score 9.8, is an authentication bypass in VMware vCenter that allows a network-based attacker to gain access.
Broadcom has released security updates addressing multiple vulnerabilities in VMware products. VMware ESX, vCenter, Workstation, and Fusion are affected. Three of these vulnerabilities have been classified as critical.
The first critical flaw is designated CVE-2026-59309 and carries a CVSS score of 9.8. It enables an authentication bypass in VMware vCenter. An attacker with network access to vCenter can exploit this vulnerability to authenticate without valid credentials and gain access to the system.
For CISOs, this represents a significant risk, particularly for environments where vCenter is directly exposed to the internet or local networks. Such a bypass circumvents central access control mechanisms and can serve as a starting point for further attacks on the virtualization infrastructure.
Broadcom recommends deploying the provided updates promptly. Organizations should prioritize their vCenter deployments and first verify the accessibility of these systems to assess the immediate risk.
Source: thehackernews.com · Published July 29, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.