CVE-2026-59309: vCenter authentication-bypass vulnerability
Published Jul 30, 2026
·Updated
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Affected Software
2 affected components
VMware vCenter
VMware VMware Directory Service
Event History
Jul 30, 2026
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-59309?
The severity of CVE-2026-59309 is critical with a CVSS score of 9.8.
2
How do I fix CVE-2026-59309?
To fix CVE-2026-59309, apply the latest security patches provided by VMware for vCenter.
3
What type of attack is associated with CVE-2026-59309?
CVE-2026-59309 is associated with an authentication bypass attack that allows unauthorized access to vCenter.
4
Who is affected by CVE-2026-59309?
Organizations using VMware vCenter and VMware Directory Service are affected by CVE-2026-59309.
5
What are the potential impacts of CVE-2026-59309?
The potential impacts of CVE-2026-59309 include unauthorized access to sensitive data and administrative privileges on the vCenter system.