Latest Broadcom VMware vCenter vulnerabilities: CVE-2026-59309 and CVE-2026-59310 #
Broadcom disclosed multiple vulnerabilities affecting certain versions of VMware vCenter:
- CVE-2026-59309: An authentication bypass vulnerability in the VMware Directory Service. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to gain unauthorized access to the system. The vulnerability has been designated CVE-2026-59309 and has been rated critical with a CVSS score of 9.8.
- CVE-2026-59310: A directory traversal vulnerability in the syslog server. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to execute arbitrary code. The vulnerability has been designated CVE-2026-59310 and has been rated critical with a CVSS score of 9.8.
The following versions are affected
- VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Versions prior to 9.1.0.0300
- VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Versions prior to 9.0.2.0100
- VMware vCenter 8.0: Versions prior to 8.0 Update 3k (U3k)
- VMware Cloud Foundation 5.x: Versions prior to 8.0 Update 3k (U3k)
- VMware Telco Cloud Platform (TCP): Versions 3.0, 4.x, 5.0.x, and 5.1.x
- VMware Telco Cloud Infrastructure (TCI): Version 3.0
What is Broadcom VMware vCenter? #
Broadcom VMware vCenter is a centralized management software platform that allows IT administrators to control, monitor, and automate virtualized server infrastructure across multiple ESXi hypervisors from a single interface.
What is the impact? #
Successful exploitation of these vulnerabilities would allow an attacker to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.
Are any updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Upgrade to version 9.1.0.0300 or later.
- VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Upgrade to version 9.0.2.0100 or later.
- VMware vCenter 8.0: Upgrade to version 8.0 Update 3k (U3k) or later.
- VMware Cloud Foundation 5.x: Async patch to vCenter 8.0 Update 3k (U3k). Refer to KB88287.
- VMware Telco Cloud Platform (TCP) 3.0, 4.x, 5.0.x, 5.1.x: Refer to KB449886.
- VMware Telco Cloud Infrastructure (TCI) 3.0: Refer to KB449886.
How to find potentially vulnerable systems with runZero #
From the Software Inventory, use the following query to locate potentially impacted assets:
(vendor:=VMware OR vendor:=Broadcom) AND (product:="vCenter Server" OR product:="vCenter" OR product:="VMware Cloud Foundation")
November 2024: CVE-2024-38812 #
Broadcom has issued a security advisory for VMware vCenter that indicates that one of the two vulnerabilities disclosed on the 17th of September, 2024, CVE-2024-38812, which was fully patched by October 21, is under active exploitation in the wild.
This vulnerability has a CVSS score of 9.8, which is considered highly critical.
What is the impact? #
An attacker with remote access to a vulnerable system could send specially crafted requests that could trigger a heap-overflow and result in remote code execution or privilege escalation into root.
Are updates or workarounds available? #
Broadcom has issued patches to resolve both vulnerabilities. Reference the Response Matrix section of the advisory for the appropriate fixed version to apply in your environment.
How to find potentially vulnerable systems with runZero #
From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:
product:vCenter
CVE-2024-38812 and CVE-2024-33813 (September 2024) #
Broadcom has issued a security advisory for two vulnerabilities that affect VMware vCenter, which exists in both VMware vSphere and VMware Cloud Foundation products.
- CVE-2024-38812 is rated critical with CVSS score of 9.8, and potentially allows for remote code execution.
CVE-2024-38813 is rated high with CVSS score of 7.5, which can result in privilege escalation into root.
What is the impact? #
An attacker with remote access to a vulnerable system could send specially crafted requests that could trigger a heap-overflow and result in remote code execution or privilege escalation into root.
Are updates or workarounds available? #
Broadcom has issued patches to resolve both vulnerabilities. Reference the Response Matrix section of the advisory for the appropriate fixed version to apply in your environment.
How to find potentially vulnerable systems with runZero #
From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:
product:vCenter