top of page
perceptive_background_267k.jpg

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit thi…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 15:06:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-59309 describes a critical authentication bypass vulnerability in VMware vCenter Server, specifically within the VMware Directory Service. A remote attacker with network access to vCenter can exploit this flaw to bypass authentication mechanisms entirely and gain unauthorized access to the system. No credentials are required for exploitation, making this a high-severity threat to virtualized enterprise environments. The vulnerability affects organizations running VMware vCenter and could allow full administrative compromise. Broadcom has published a security advisory addressing the issue. The NVD listing is currently awaiting full analysis and scoring. Given the nature of authentication bypass vulnerabilities in vCenter, this poses significant risk to cloud and virtualization infrastructure.

Technical details

Mitigation steps:

Affected products:

VMware vCenter Server
VMware Directory Service

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page