Broadcom has patched two critical flaws in VMware vCenter Server that let an attacker with network access walk straight past the login screen and run code on the system that controls a company's entire virtual infrastructure. Both carry a CVSS score of 9.8 out of 10, and neither requires the attacker to have an account first.
vCenter is the central console for VMware vSphere environments. Administrators use it to manage ESXi hosts, spin up and destroy virtual machines, and allocate resources across the estate. Whoever controls vCenter effectively controls every workload running underneath it, which is why ransomware crews and intrusion groups have repeatedly gone after it, as Scattered Spider did when it used vCenter to dump domain credentials and deploy ESXi ransomware.
What is affected
The two issues were published on 29 July 2026 in Broadcom advisory VMSA-2026-0006. CVE-2026-59309 is an authentication bypass in the VMware Directory Service, the component that decides who is allowed into the vCenter management plane. CVE-2026-59310 is a directory traversal flaw in the vCenter Syslog server, meaning an attacker can escape the folder the service is supposed to stay inside and drop files where they should not go, which in this case leads to arbitrary code execution.
Fixed builds are 9.1.0.0300 for vCenter 9.1.x, 9.0.2.0100 for 9.0.x, and 8.0 U3k for vCenter 8.0. VMware Cloud Foundation 5.x customers need the async patch to 8.0 U3k. Telco Cloud Platform and Telco Cloud Infrastructure users should follow Broadcom KB449886.
What you should do
Patch now. Broadcom states there are no workarounds for either flaw, so the vendor updates are the only remediation available. If your maintenance window is weeks out, treat this as the exception.
The one piece of good news is exposure. Management interfaces like vCenter are usually confined to internal or dedicated management networks, which cuts the risk of opportunistic internet scanning. That is a real mitigation, but a partial one: it does nothing to stop an attacker who already has a foothold inside the network, which is precisely the position ransomware operators reach before they start hunting for hypervisors.
Is it being exploited
Not yet, as far as anyone can tell. Rapid7's Emergent Threat Response team reports no known exploitation or scanning in the wild for either CVE at the time of publication, and no public proof of concept code. That window historically closes fast. Rapid7 notes vCenter Server has landed on CISA's Known Exploited Vulnerabilities catalog ten times before for other issues, a track record that leaves little doubt attackers will look at these two.
The analysis comes from the Rapid7 Emergent Threat Response team in their original write-up, published 30 July 2026. It follows a run of unauthenticated flaws in infrastructure management tools this month, including a critical JetBrains TeamCity bug that hands over build servers and a built-in password in Cisco firewall management software now under active attack.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.