Last Updated: Friday, August 14, 2026 5:45 PM
CVSSv3: 9.8
What’s Happening
There is a critical Auth Bypass vulnerability in Broadcom’s VMware vCenter, CVE-2026-59309. Published in Broadcom’s July 29th, 2026 security advisory, the security researchers who discovered the vulnerability published a walkthrough for it on the same day. There is a patch available for the vulnerability. There is no other workaround. It has been reported as EITW by independant sources.
The vulnerability bypasses the authorization requirement granting access to any user account, including administrators, via the vCenter LDAP server. Given administrative access to the LDAP server, an attacker can create a new admin account allowing them to pivot to the vCenter Web-Client.
Broadcom’s Advisory:
Atredis’ Walkthrough:
https://github.com/atredispartners/advisories/blob/master/2026/ATREDIS-2026-0008.md
Actions
Patch immediately. Broadcom has released a security update, you can find their patch matrix in their security advisory.
Of course, patching isn’t the same as eviction. You’ll also want to check your vCenter environment for unknown admin users (or unknown users in general).
Notes
While this vulnerability hasn’t been reported as EITW, the other vulnerability in Atredis’ walkthrough is also currently being exploited in the wild.
vCenter User Account Management Docs:
vCenter Default Users List:
https://knowledge.broadcom.com/external/article/407968/list-of-vcenter-server-user-accounts-cre.html
CVE-2026-59309:
