Latest Broadcom VMware vCenter vulnerabilities: CVE-2026-59309 and CVE-2026-59310 #

Broadcom disclosed multiple vulnerabilities affecting certain versions of VMware vCenter:

  • CVE-2026-59309: An authentication bypass vulnerability in the VMware Directory Service. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to gain unauthorized access to the system. The vulnerability has been designated CVE-2026-59309 and has been rated critical with a CVSS score of 9.8.
  • CVE-2026-59310: A directory traversal vulnerability in the syslog server. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to execute arbitrary code. The vulnerability has been designated CVE-2026-59310 and has been rated critical with a CVSS score of 9.8.

The following versions are affected

  • VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Versions prior to 9.1.0.0300
  • VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Versions prior to 9.0.2.0100
  • VMware vCenter 8.0: Versions prior to 8.0 Update 3k (U3k)
  • VMware Cloud Foundation 5.x: Versions prior to 8.0 Update 3k (U3k)
  • VMware Telco Cloud Platform (TCP): Versions 3.0, 4.x, 5.0.x, and 5.1.x
  • VMware Telco Cloud Infrastructure (TCI): Version 3.0

    What is Broadcom VMware vCenter? #

    Broadcom VMware vCenter is a centralized management software platform that allows IT administrators to control, monitor, and automate virtualized server infrastructure across multiple ESXi hypervisors from a single interface.

    What is the impact? #

    Successful exploitation of these vulnerabilities would allow an attacker to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.

    Are any updates or workarounds available? #

    Users are encouraged to update to the latest version as quickly as possible:

    • VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Upgrade to version 9.1.0.0300 or later.
    • VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Upgrade to version 9.0.2.0100 or later.
    • VMware vCenter 8.0: Upgrade to version 8.0 Update 3k (U3k) or later.
    • VMware Cloud Foundation 5.x: Async patch to vCenter 8.0 Update 3k (U3k). Refer to KB88287.
    • VMware Telco Cloud Platform (TCP) 3.0, 4.x, 5.0.x, 5.1.x: Refer to KB449886.
    • VMware Telco Cloud Infrastructure (TCI) 3.0: Refer to KB449886.

      How to find potentially vulnerable systems with runZero #

      From the Software Inventory, use the following query to locate potentially impacted assets:

      (vendor:=VMware OR vendor:=Broadcom) AND (product:="vCenter Server" OR product:="vCenter" OR product:="VMware Cloud Foundation")

      November 2024: CVE-2024-38812 #

      Broadcom has issued a security advisory for VMware vCenter that indicates that one of the two vulnerabilities disclosed on the 17th of September, 2024,  CVE-2024-38812, which was fully patched by October 21, is under active exploitation in the wild.

      This vulnerability has a CVSS score of 9.8, which is considered highly critical.

      What is the impact? #

      An attacker with remote access to a vulnerable system could send specially crafted requests that could trigger a heap-overflow and result in remote code execution or privilege escalation into root.

      Are updates or workarounds available? #

      Broadcom has issued patches to resolve both vulnerabilities. Reference the Response Matrix section of the advisory for the appropriate fixed version to apply in your environment.

      How to find potentially vulnerable systems with runZero #

      From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:

      product:vCenter



      CVE-2024-38812 and CVE-2024-33813 (September 2024) #

      Broadcom has issued a security advisory for two vulnerabilities that affect VMware vCenter, which exists in both VMware vSphere and VMware Cloud Foundation products.

      • CVE-2024-38812 is rated critical with CVSS score of 9.8, and potentially allows for remote code execution.
      • CVE-2024-38813 is rated high with CVSS score of 7.5, which can result in privilege escalation into root.

      What is the impact? #

      An attacker with remote access to a vulnerable system could send specially crafted requests that could trigger a heap-overflow and result in remote code execution or privilege escalation into root.

      Are updates or workarounds available? #

      Broadcom has issued patches to resolve both vulnerabilities. Reference the Response Matrix section of the advisory for the appropriate fixed version to apply in your environment.

      How to find potentially vulnerable systems with runZero #

      From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:

      product:vCenter

      Written by runZero Team

      Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

      More about runZero Team

      Written by Matthew Kienow

      Matthew Kienow is a software engineer and security researcher. Matthew previously worked on the Recog recognition framework, AttackerKB as well as Metasploit's MSF 5 APIs. He has also designed, built, and successfully deployed many secure software solutions; however, often he enjoys breaking them instead. He has presented his research at various security conferences including DerbyCon, Hack In Paris, and CarolinaCon. His research has been cited by CSO, Threatpost and SC Magazine.

      More about Matthew Kienow
      Subscribe Now

      Get the latest news and expert insights delivered in your inbox.

      Welcome to the club! Your subscription to our newsletter is successful.

      Explore more runZero

      Product
      Announcing runZero 5.0: Exposure management built to outpace AI-driven attacks
      When you're up against AI, every minute counts. Get deep, actionable intelligence across your entire attack surface to close the gaps and hold the...
      Product Videos
      runZero 5.0: Platform Demo
      With the new 5.0 release, runZero is giving defenders the edge they need to succeed in the AI-attack era.
      runZero Perspective
      BOD 26-04: A new era of prioritized remediation
      A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
      runZero Perspective
      Dawn of the apex agentic adversary
      When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
      Webcasts
      Mind the gaps: securing the modern IT/OT attack surface
      In this webcast, HD Moore and GigaOm Analyst Chris Ray discuss key methods for hardening OT defenses and share insights from the new OT report.
      Webcasts
      runZero Hour, Ep. 32: AI-pocalypse now? Why the 2026 DBIR is actually good news
      In this episode of runZero Hour, Tod Beardsley, Brianna Cluck, and Verizon's Alex Pinto broke down 2026 DBIR trends, AI threats, and runZero 5.0.
      Podcasts
      The shadow era AI, exploits, and cybersecurity's 90s comeback
      HD Moore explains how AI is turning hacking back to the 90s, generating permanent exploit skeleton keys and breaking traditional defense.
      Talks
      Identifying exposures at scale with BloodHound OpenGraph
      Traditional exposure management misses hidden attack paths. Learn how BloodHound and Cypher queries can uncover vulnerabilities beyond individual...

      See Results in Minutes

      See & secure your total attack surface. Even the unknowns & unmanageable.