https://reddit.com/r/netsec/comments/1wn37be/vcenter_preauth_rce_cve20265930959310/: vCenter pre-auth RCE: CVE-2026-59309/59310
Published Sep 22, 2026
·Updated
Affected Software
1 affected component
VMware vCenter Server
Frequently Asked Questions
1
Does exploitation require valid vCenter credentials?
No. Both issues are described as pre-authentication vulnerabilities, so an attacker would not need to authenticate before attempting exploitation.
2
What could an attacker achieve by combining these issues?
The reported chain combines an authentication bypass with a syslog path traversal and can result in remote code execution on VMware vCenter Server.