Affected Systems

VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x. Additional critical flaws affect VMware ESX, Workstation, and Fusion across multiple versions.

Exploitation Status

No evidence of active exploitation reported by Broadcom as of advisory publication. No public PoC mentioned for CVE-2026-59309.

Business Impact

CVE-2026-59309 enables unauthenticated remote attackers with network access to vCenter to bypass authentication and gain unauthorized system access. This is a pre-authentication vulnerability with CVSS 9.8, representing complete compromise of vCenter infrastructure. Additional critical flaws include CVE-2026-59310 (directory traversal RCE in vCenter, CVSS 9.8) and CVE-2026-47876 (VM escape to ESXi host code execution, CVSS 9.3). Organizations running affected vCenter versions face risk of full virtualization infrastructure compromise.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately inventory all VMware vCenter Server instances and identify versions affected by CVE-2026-59309, CVE-2026-59310
  • Apply Broadcom security patches: upgrade vCenter to 9.1.0.0300, 9.0.2.0100, or 8.0 U3k depending on deployment version
  • Upgrade VMware ESXi hosts to ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, or ESXi80U3k-25595708 to address CVE-2026-47876 VM escape vulnerability
  • Review vCenter access logs for anomalous authentication patterns or unauthorized access attempts prior to patching
  • Restrict network access to vCenter Server to trusted management networks and enforce firewall rules until patches are deployed