CVE-2026-59309 & CVE-2026-59310: VMware vCenter's Critical Auth Bypass and RCE Duo

Technical analysis and remediation for VMware vCenter Server critical authentication bypass and remote code execution vulnerabilities.

CVE-2026-59309 & CVE-2026-59310: VMware vCenter's Critical Auth Bypass and RCE Duo
Photo by İsmail Enes Ayhan / Unsplash
📌
Security Roundup Series: Week of July 31, 2026 • 5 min read deep dive

Broadcom VMware patched a pair of critical vulnerabilities in vCenter Server that allow unauthenticated remote attackers on the network to bypass authentication mechanisms and execute arbitrary code with root privileges across virtualized infrastructure.

🚨
Vulnerability Intelligence: CVE IDs: CVE-2026-59309 (Auth Bypass) & CVE-2026-59310 (RCE) Severity & CVSS: Critical 9.8 / 9.8 Impact: Complete takeover of VMware vCenter Server management control plane Affected Versions: VMware vCenter Server 7.0 & 8.0 lines

What's Affected

VMware vCenter Server installations managing ESXi hypervisors. Because vCenter controls identity, VM provisioning, virtual networking, and storage across entire datacenters, compromising vCenter yields root control over all guest virtual machines.

The Vulnerability Chain

The first flaw (CVE-2026-59309) exploits an implementation flaw in the DCE/RPC protocol implementation to bypass authentication. Attackers then chain this with CVE-2026-59310 to achieve remote heap overflow and root command execution.

Remediation

✅
Action: Apply VMware's official vCenter Server patch updates immediately. Restrict network access to vCenter management ports (443, 80, 2012, 2014) to dedicated admin VLANs.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther