Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, government, defence] · au_impact: false

CVE-2026-59309

Summary

An authentication bypass in VMware vCenter Server that lets an attacker with network access gain administrative control of the platform, scored CVSS 9.8.

Details

vCenter is the control plane for a virtual estate, so administrative control there is control of every guest the platform runs and of the backup and snapshot machinery around them — the reason vCenter flaws have been a fixture of ransomware intrusions. The digest recorded it alongside CVE-2026-59310, a directory-traversal flaw in the same product allowing remote code execution, and the pair is the familiar escalation pattern: bypass the authentication, then reach the code-execution path. Both are network-reachable, which puts the priority on whether vCenter is exposed beyond the management network.

Attribute Detail
CVE CVE-2026-59309
CVSS 9.8
Vendor / product VMware (vCenter Server)
Reported in the digest 2026-07-30

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-30.md