GPU VulnDB

Database/Control plane, storage & DevOps

VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network access

CVE-2026-59309Control plane, storage & DevOpscurated

Impact

An unauthenticated attacker with network access to vCenter bypasses authentication entirely and gains access to the system. vCenter owns every VM and host in the cluster, so this is total virtualization-estate compromise. Public reporting describes active exploitation at scale across many countries.

Who can reach it

Network access to vCenter. No credentials required.

What to do

Apply the Broadcom fix immediately - this and its sibling directory-traversal bug are being exploited in the wild. vCenter appliance patch plus restart. Given the exploitation reports, do not treat patching alone as sufficient: hunt for new/modified SSO accounts, unexpected scheduled tasks and altered vpxd logs before calling it clean.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.