VMware vCenter - Unauthenticated Directory Traversal to RCE & Unauthenticated Auth Bypass
VMware vCenter is a centralized management platform that controls multiple virtual machines and ESXi hosts from a single interface CVE-2026-59309 Critical authentication bypass (CVSS 9.8) in VMware Directory Service that allows attackers to bypass login credentials and gain unauthorized access to vCenter management without authentication. CVE-2026-59310 Critical (CVSS 9.8) and involves a directory traversal vulnerability in the Syslog server, enabling attackers to read unauthorized files and execute arbitrary code on the system. Both vulnerabilities require only network access to the vCenter server and have no workarounds—patches are mandatory to prevent complete system compromise.



