Skip to content
Rush Commerce
Software & Dev3 min read

vCenter CVSS 9.8 CVEs: no workaround, patch this week

Broadcom patched two critical vCenter flaws — auth bypass and RCE, both CVSS 9.8, no workarounds. If you run vSphere, the fix is the only mitigation.

Broadcom published VMSA-2026-0006 on July 29, and two of the five bugs in it are the kind you stop your week for: CVE-2026-59309 and CVE-2026-59310, both CVSS 9.8, both remotely exploitable by an unauthenticated attacker with network access to vCenter Server. There are no workarounds for either. The patch is the mitigation — that's the whole list.

What actually happened

Per Broadcom's advisory and Rapid7's analysis, CVE-2026-59309 is an authentication bypass in VMware Directory Service: reach vCenter over the network and you're inside the management plane, no credentials required. CVE-2026-59310 is a directory traversal in the vCenter Syslog server that leads to arbitrary code execution. Chain them and an anonymous scanner owns the box that controls every VM you run.

Fixed vCenter builds are 8.0 U3k, 9.0.2.0100, and 9.1.0.0300. The same advisory covers CVE-2026-47876, a CVSS 9.3 out-of-bounds write in the VMXNET3 virtual NIC on ESX, plus two low-to-moderate ESX issues. Cloud Foundation 5.x and older Telco Cloud Platform releases need async patches referenced in Broadcom's KB articles rather than a straight upgrade.

At publication there was no known exploitation and no public proof-of-concept for either critical CVE. That is a scheduling detail, not a reprieve. vCenter has a long history of being reverse-engineered fast once patches ship, because the patch itself tells attackers where to look.

Why it matters for your business

If you're a small business, you probably don't run vSphere. Your managed service provider does, and your servers are tenants on it. That's the real exposure: a hypervisor management plane compromise isn't one server, it's every VM on the cluster — file servers, the accounting box, domain controllers, backups if they live on the same storage.

Two things to do today. First, if you own the vCenter, patch to the builds above and check that port 443 on your management interface is not reachable from the internet or from your general office VLAN. Management planes belong on a segmented network you reach over VPN, full stop. Second, if someone else owns it, send them the advisory number and ask three questions in writing: what version are you on, when will you patch, and is the vCenter web interface internet-facing. A vendor who can't answer that in a day is telling you something.

Then check whether your backups would survive the hypervisor being owned. If your only copy of everything lives as a VM on the same cluster, you don't have a backup — you have a second copy of the blast radius.

Key takeaways

  • VMSA-2026-0006 (July 29) includes CVE-2026-59309 and CVE-2026-59310, both CVSS 9.8 and both exploitable by unauthenticated attackers with network access to vCenter
  • Broadcom lists no workarounds for either — patching to vCenter 8.0 U3k, 9.0.2.0100, or 9.1.0.0300 is the only fix
  • The advisory also covers CVE-2026-47876, a CVSS 9.3 VMXNET3 out-of-bounds write on ESX
  • No known exploitation or public PoC at publication; vCenter bugs historically get weaponized quickly after patches ship
  • If your MSP runs the cluster, get the version, the patch date, and internet exposure in writing — and verify your backups aren't VMs on that same cluster

Not sure who owns the hypervisor your business runs on? We map what's exposed, get management planes off the public internet, and make sure your backups survive the layer underneath them. See how we harden your stack or book an exposure review.

Sources: Broadcom VMSA-2026-0006, Rapid7.

  • #vmware
  • #vcenter
  • #cve-2026-59309
  • #security
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.