← All Advisories

CVE-2026-59309

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-59309

Key Details

CVECVE-2026-59309
CVSSCVSS 9.8 (Critical).
Affected productsVMware vCenter Server
Classified asCWE-303 (Incorrect Implementation of Authentication Algorithm)
Exploitation prediction (EPSS)8% probability of exploitation in the next 30 days (94% percentile) -- FIRST.org's EPSS model.

What to Know

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-59309
Vendor advisoryhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017