CVE-2026-59309: VMware vCenter Server
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Affected products
- VMware vCenter Server: before 8.0 (fixed in 8.0); version 8.0 only; from 9.0, before 9.0.2.0100 (fixed in 9.0.2.0100); from 9.1, before 9.1.0.0300 (fixed in 9.1.0.0300)
Published 2026-07-30. Last modified 2026-08-25.