← All Advisories

Critical VMware vCenter Authentication Bypass in Directory Service Scores 9.8

Last refreshed2026-09-26

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-59309

Key Details

CVECVE-2026-59309
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsVMware vCenter Server
Classified asCWE-303 (Incorrect Implementation of Authentication Algorithm)
Exploitation prediction (EPSS)0.61% probability of exploitation in the next 30 days (47% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
VMwarevCenter Server
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

What to Do

Monitor VMware's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-59309
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-59309
Vendor advisoryhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017