A 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter bypass authentication entirely, plus a directory-traversal RCE and a VM-escape bug in the VMXNET3 adapter.
Broadcom published emergency fixes on July 29, 2026 for three critical VMware vulnerabilities across vCenter, ESX, Workstation, and Fusion. CVE-2026-59309 (CVSS 9.8) is a straightforward authentication bypass: a malicious actor with network access to vCenter can skip authentication outright and reach the system without valid credentials. It's paired with CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw enabling code execution, and CVE-2026-47876 (CVSS 9.3), an out-of-bounds write in the VMXNET3 virtual network adapter that allows a VM escape onto the host. Fixes landed in vSphere Foundation 9.1.0.0300, 9.0.2.0100, vCenter 8.0 U3k, and an async patch for Cloud Foundation 5.x. Broadcom says it has no evidence of in-the-wild exploitation yet, but characterizes all three as emergency-severity with no available workaround, meaning the patch is the only mitigation.
Why it matters
vCenter is the identity and control plane for an entire virtualization estate, so an authentication bypass here isn't scoped to one VM, it's every host and guest the management server touches. Chained with the VM-escape bug, the combination lets an attacker skip the login, execute code, and break out of guest isolation in one campaign, which is a materially different risk than any of the three in isolation.
This is the same shape of flaw as the Certighost Active Directory exploit covered earlier: infrastructure that's supposed to be the trust anchor for everything downstream turns out to have a gap in the authentication check itself. No workaround means patching now, not scheduling it for the next maintenance window.
Source: The Hacker News
Related on Start with Identity
- BlogNetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured
- BlogTwo PaperCut flaws chain into unauthenticated code execution, and the patch has bypasses
CVE-2026-81578 bypasses authentication on the PaperCut web management interface, and CVE-2026-82078 turns a config edit into remote code execution. Exploitation
- BlogA CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later r
- CVEFortinet follow-on SSO SAML bypass after the 59718 patch
A second FortiCloud SSO SAML bypass that hits devices already patched for CVE-2025-59718 and CVE-2025-59719. Actively exploited. CISA guidance 28 January 2026.
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- CVEIvanti Sentry authentication bypass
Ivanti Sentry (MobileIron Sentry) skipped authentication on an administrative API. CISA KEV. August 2023. The gateway in front of EPMM had its own unlocked door