- Sources: VMSA-2026-0006, NVD CVE-2026-59309, GHSA-8f48-75j5-mrf7, BleepingComputer
- Summary: The advisory carries an issue and initial publication date of 2026-07-29 and covers five CVEs across a 2.7 to 9.8 CVSSv3 range, with the workaround field reading None for every one. CVE-2026-59309 is an authentication bypass in the VMware Directory Service and CVE-2026-59310 a directory traversal in the vCenter Syslog server, both reachable by an actor with network access to vCenter and both scored 9.8. CVE-2026-47876 is an out-of-bounds write in the VMXNET3 virtual network adapter scored 9.3, exploitable by a local administrator inside a guest to execute code on the ESX host, and non-VMXNET3 adapters are unaffected. The named fixed versions are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k, with CVE-2026-59309 first fixed in 9.1.0.0200 and 9.1.0.0300 named only as the most recent cumulative version, and ESX builds ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, and ESXi80U3k-25595708. Cloud Foundation 5.x, vSphere Foundation, and the Telco Cloud products are routed through KB88287 and KB449886. Broadcom states the issues were privately reported, and CISA's SSVC entry on CVE-2026-59309 records exploitation as none, automatable as yes, and technical impact as total. The advisory's own FIRST calculator link for CVE-2026-47876 and the GitHub advisory record give different vector strings for the same 9.3 score, so no vector string is asserted here.
- Why it matters: An unauthenticated authentication bypass and an unauthenticated remote code execution path on vCenter, plus a guest-to-host escape, with no workaround offered for any of the five, leaves patching as the only available control.
- Follow-up: CISA's SSVC record gives exploitation as none and automatable as yes, so track whether exploitation is observed.
send feedback on this story