top of page
perceptive_background_267k.jpg

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit thi…

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 16:01:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-59309 describes a critical authentication bypass vulnerability in VMware vCenter Server, specifically within the VMware Directory Service component. A remote attacker with network access to vCenter can exploit this flaw to bypass authentication mechanisms entirely. Successful exploitation grants unauthorized access to the vCenter system without valid credentials. The vulnerability poses a significant risk to virtualized infrastructure environments managed by VMware vCenter. The issue is documented by NVD and a security advisory has been published by Broadcom. No specific exploitation details or patches are mentioned in the article, but the severity is rated High. Organizations running VMware vCenter should monitor for patches and apply mitigations promptly.

Technical details

Mitigation steps:

Affected products:

VMware vCenter Server
VMware Directory Service

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page