CVE-2026-59309: Critical Auth Bypass in Broadcom VMware vCenter

Last Updated: Friday, August 14, 2026 5:45 PM

CVSSv3: 9.8

What’s Happening

There is a critical Auth Bypass vulnerability in Broadcom’s VMware vCenter, CVE-2026-59309. Published in Broadcom’s July 29th, 2026 security advisory, the security researchers who discovered the vulnerability published a walkthrough for it on the same day. There is a patch available for the vulnerability. There is no other workaround. It has been reported as EITW by independant sources.

The vulnerability bypasses the authorization requirement granting access to any user account, including administrators, via the vCenter LDAP server. Given administrative access to the LDAP server, an attacker can create a new admin account allowing them to pivot to the vCenter Web-Client.

Broadcom’s Advisory:

Atredis’ Walkthrough:

https://github.com/atredispartners/advisories/blob/master/2026/ATREDIS-2026-0008.md

Actions

Patch immediately. Broadcom has released a security update, you can find their patch matrix in their security advisory.

Of course, patching isn’t the same as eviction. You’ll also want to check your vCenter environment for unknown admin users (or unknown users in general).

Notes

While this vulnerability hasn’t been reported as EITW, the other vulnerability in Atredis’ walkthrough is also currently being exploited in the wild.

vCenter User Account Management Docs:

https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/vcenter-configuration/configuring-vcenter-server-using-the-appliance-shell/managing-local-user-accounts-in-vcenter-server/get-a-list-of-the-local-user-accounts.html

vCenter Default Users List:

https://knowledge.broadcom.com/external/article/407968/list-of-vcenter-server-user-accounts-cre.html

CVE-2026-59309:

https://www.cve.org/CVERecord?id=CVE-2026-59309

4 Likes

While this vulnerability hasn’t been reported as EITW, the other vulnerability in Atredis’ walkthrough is currently being exploited in the wild.

Without being able to go into more detail, consider this vulnerability as “actively exploited”.

5 Likes

Seen some reports that the patch can cause latency and potentially outages.

Moving to Threat Intel with exploitation report.

1 Like