CVE-2026-59309
Summary
An authentication bypass in VMware vCenter Server that lets an attacker with network access gain administrative control of the platform, scored CVSS 9.8.
Details
vCenter is the control plane for a virtual estate, so administrative control there is control of every guest the platform runs and of the backup and snapshot machinery around them — the reason vCenter flaws have been a fixture of ransomware intrusions. The digest recorded it alongside CVE-2026-59310, a directory-traversal flaw in the same product allowing remote code execution, and the pair is the familiar escalation pattern: bypass the authentication, then reach the code-execution path. Both are network-reachable, which puts the priority on whether vCenter is exposed beyond the management network.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-59309 |
| CVSS | 9.8 |
| Vendor / product | VMware (vCenter Server) |
| Reported in the digest | 2026-07-30 |
Related Pages
- Cve 2026 59310 Vmware Vcenter Dir Traversal (companion directory-traversal flaw in the same product)
- Source article
Sources: raw/digests/Cyber-Digest-2026-07-30.md