Skip to content

Critical VMware vCenter vulnerabilities prompt urgency: what you need to know and how to respond

If you manage VMware vCenter, a pair of critical flaws could let an attacker gain control over your management plane without a login. That combination of unauthenticated access and remote code execution is exactly the sort of risk that can escalate quickly in small businesses and IT shops alike.

Here’s what happened, why it matters, and practical steps you can take to protect your environment.

What happened

In late July 2026, Broadcom, the parent company of VMware, published security advisory VMSA-2026-0006 addressing several vulnerabilities across VMware products, including two critical flaws in VMware vCenter Server:

  • CVE-2026-59309 – an authentication bypass that could allow an attacker with network access to vCenter to gain unauthorized control.
  • CVE-2026-59310 – a directory traversal vulnerability in the vCenter syslog server that could enable arbitrary code execution on the ESX/host with network access.

Both have high urgency, with CVSS base scores up to 9.8 in vendor reports and extensive guidance in security briefs.

Vendor updates noted that express patches are available for the affected versions, including VMware vCenter 8.0 U2f and 8.0 U3k. The patches aim to close the unauthenticated access gap and prevent exploitation of the directory traversal flaw.

According to the advisories, there is no separate workaround documented beyond applying the patches. Organizations should act promptly to patch and validate their vCenter deployments.

Why it matters

vCenter is the central management point for many VMware environments. If an attacker can access it unauthenticated, they could potentially move laterally into connected hosts and reduce operational security. For small businesses and creators running virtualized workloads, a compromise could mean downtime, data exposure, or unauthorized changes to virtual machines.

Security researchers and incident responders emphasize prioritizing patching and testing in a controlled environment before broad deployment.

Practical steps you can take

  • Check what you’re running: Identify whether your environment uses VMware vCenter Server and which version you’re on. Look for 8.0 U2f, 8.0 U3k, or earlier builds that may be affected.
  • Plan and test the patch: Schedule a patch window, back up critical configurations, and test patches in a staging environment if possible.
  • Apply the patches: Install the express patches for 8.0 U2f or 8.0 U3k as released by VMware/Broadcom, following the official guidance in VMSA-2026-0006.
  • Verify and monitor: After patching, verify that vCenter services come up cleanly and run a vulnerability scan or inventory check to confirm the risk is mitigated.
  • Limit exposure in the meantime (if patching can’t be done immediately): review access control to management interfaces, and monitor for unusual login attempts or management changes.
  • Stay informed: Subscribe to VMware/Broadcom advisories and security bulletins for updates on patches and any follow-on guidance.

Final thoughts

Two critical flaws in a core management platform are a reminder to keep patching cycles tight and to test updates before they land in production. If you run VMware vCenter, make patching a top priority this week, and share learnings with your team.

VMware security advisory VMSA-2026-0006

Rapid7 blog on CVE-2026-59309/59310

Kudelski Security – VMware advisory coverage

Leave a Reply

Your email address will not be published. Required fields are marked *