DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-59309PUBLISHED: 2026-07-29
CRITICALCVE-2026-59309

VMware vCenter Authentication Bypass in Directory Service

VENDOR: Broadcom (VMware)//PRODUCT: VMware vCenter Server
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

Published July 29, 2026 as part of VMSA-2026-0006, this critical authentication bypass in the VMware Directory Service allows a remote unauthenticated attacker with network access to vCenter to bypass authentication controls and gain unauthorized full access to the management platform. Since vCenter centrally manages ESXi hosts, VMs, and permissions across datacenter infrastructure, successful exploitation provides a high-value pivot point for lateral movement. No workaround is available; no in-the-wild exploitation confirmed by Broadcom at time of publication.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSVMware Cloud Foundation/vSphere Foundation 9.1.x (fixed in 9.1.0.0300), 9.0.x (fixed in 9.0.2.0100), 8.0 U3k; also vCenter 5.x
  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
  • https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
  • https://gbhackers.com/critical-vmware-vcenter-flaws/amp/
  • https://cybersecuritynews.com/vmware-flaws-allow-authentication-bypass/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn