CVE-2026-59309 & CVE-2026-59310: VMware vCenter's Critical Auth Bypass and RCE Duo
Technical analysis and remediation for VMware vCenter Server critical authentication bypass and remote code execution vulnerabilities.
Broadcom VMware patched a pair of critical vulnerabilities in vCenter Server that allow unauthenticated remote attackers on the network to bypass authentication mechanisms and execute arbitrary code with root privileges across virtualized infrastructure.
CVE-2026-59309 (Auth Bypass) & CVE-2026-59310 (RCE)
Severity & CVSS: Critical 9.8 / 9.8
Impact: Complete takeover of VMware vCenter Server management control plane
Affected Versions: VMware vCenter Server 7.0 & 8.0 lines
What's Affected
VMware vCenter Server installations managing ESXi hypervisors. Because vCenter controls identity, VM provisioning, virtual networking, and storage across entire datacenters, compromising vCenter yields root control over all guest virtual machines.
The Vulnerability Chain
The first flaw (CVE-2026-59309) exploits an implementation flaw in the DCE/RPC protocol implementation to bypass authentication. Attackers then chain this with CVE-2026-59310 to achieve remote heap overflow and root command execution.