Database/Control plane, storage & DevOps
Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenter
CVE-2026-53475Control plane, storage & DevOpscurated
Impact
The agent hardcodes insecure TLS when talking to vCenter, so a machine-in-the-middle harvests vCenter administrator credentials in transit - unauthorized admin access to the virtualization estate.
Who can reach it
Network position between the migration agent and vCenter.
What to do
Update the assisted-migration-agent to a build including the upstream fix, and rotate the vCenter admin credentials the agent used. Retire the agent when the migration completes rather than leaving it deployed.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.