Database/Control plane, storage & DevOps
VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network access
Impact
An unauthenticated attacker with network access to vCenter bypasses authentication entirely and gains access to the system. vCenter owns every VM and host in the cluster, so this is total virtualization-estate compromise. Public reporting describes active exploitation at scale across many countries.
Who can reach it
Network access to vCenter. No credentials required.
What to do
Apply the Broadcom fix immediately - this and its sibling directory-traversal bug are being exploited in the wild. vCenter appliance patch plus restart. Given the exploitation reports, do not treat patching alone as sufficient: hunt for new/modified SSO accounts, unexpected scheduled tasks and altered vpxd logs before calling it clean.
References
Related entries
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCVE-2026-59310 · VMware vCenter (Syslog server directory traversal to RCE)Critical
- Gitea: unauthenticated remote code execution via the diffpatch API installing Git hooksCVE-2026-60004 · Gitea (diffpatch API / Git hook installation)Critical
- JetBrains TeamCity: Deserialization in the agent polling protocolCVE-2026-63077 · JetBrains TeamCityCritical
- Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-basedCVE-2026-65791 · Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+)Critical
- Windows Services for NFS: use-after-free in the ONCRPC XDR driver allows unauthenticated remote code executionCVE-2026-69595 · Windows Services for NFS (ONCRPC XDR driver)Critical
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCVE-2026-72217 · Linux SUNRPC (xdr_buf_to_bvec, nfsd write path)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.