Your hypervisor management plane can be taken over with zero credentials, and the vendor says there is no workaround.

CVE-2026-59309 — CVSS 9.8 — an authentication bypass in VMware Directory Service, the identity layer behind vCenter Single Sign-On. Disclosed by Broadcom in VMSA-2026-0006. No exploitation observed in the wild yet. That gap is your window.

WHAT ACTUALLY HAPPENED

The flaw lives in vmdir, the component that underpins vCenter SSO. An attacker with network access to vCenter bypasses authentication entirely: no credentials, no user interaction, no privileges required, no phishing step.

It shipped alongside CVE-2026-59310, also CVSS 9.8 — a directory traversal in the vCenter syslog service allowing unauthenticated remote code execution. One gets you in as a trusted identity, the other gets you code on the appliance.

Affected: vCenter Server 8.0 before 8.0 Update 3k (build 25600417), 9.0.x before 9.0.2.0100, and 9.1.x before 9.1.0.0300. VMware Cloud Foundation 5.x needs the async patch to vCenter 8.0 Update 3k.

Broadcom is explicit: there are no workarounds for either flaw. Patching is the only remediation.

WHY THE MANAGEMENT PLANE CHANGES THE MATH

vCenter is not a server. It is the control point for every VM, datastore and virtual network in the estate. An authentication bypass there is not one compromised host — it is every workload at once, from a single reachable address.

The comfort story is always "management interfaces are internal only". That assumption dies the moment one VPN profile, one jump host or one flat VLAN gives an attacker network adjacency. Ransomware crews have industrialised exactly this path: reach the hypervisor, encrypt datastores, and never touch an endpoint agent.

No public proof-of-concept yet is not safety. It is a maintenance window with an expiry date.

WHAT TO DO NOW

PATCH TO 8.0 U3K, 9.0.2.0100 OR 9.1.0.0300 — there is no configuration change that substitutes for this; it is patch or stay exposed.

PROVE YOUR MANAGEMENT NETWORK IS ISOLATED — enumerate every route, VPN profile and jump host that can reach vCenter on 443 today, then remove what should not be there.

TREAT CLOUD FOUNDATION 5.X SEPARATELY — it requires the async patch to vCenter 8.0 Update 3k; do not assume your base release covers it.

BASELINE SSO AUTHENTICATION LOGS NOW — capture what normal looks like before a PoC lands, so anomalous sessions stand out when it does.

Patching before exploitation is the cheapest security work you will ever do. Patching after is called incident response.

If an attacker landed on your corporate VLAN tonight, how many hops away is your vCenter?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.