Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-59309PATCHED
VMware · Cloud Foundation

vCenter authentication-bypass vulnerability

Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Affected Products

VendorProductVersions
VMwareCloud Foundation9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 3.0, 5.1.x, 5.0.x, 4.x, 3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
vmwarevsphere foundationmitre_affected90%
vmwarevcentermitre_affected90%
vmwaretelco cloud infrastructuremitre_affected90%
vmwaretelco cloudmitre_affected90%

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Related News (5 articles)

Tier D
BleepingComputer13d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
→ No new info (linked only)
Tier B
CCCS Canada13d ago
VMware security advisory (AV26-763)
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-59309 | VMware vCenter VMware Directory Service improper authentication
→ No new info (linked only)
Tier D
Heise Security13d ago
VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits VMware (30 juillet 2026)
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
9.1.0.03009.0.2.01008.0 U3k
CWECWE-303
PublishedJul 30, 2026
Last enriched13d ago
Trending Score17
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 137
CRITICALCVE-2026-47876
VMXNET3 out-of-bounds write vulnerability
Trending: 14
HIGHCVE-2026-41703
Out-of-bounds read vulnerability
Trending: 14
HIGHCVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Trending: 13
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 11

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Jul 30, 2026