# CVE-2026-59309

## Summary

- **CVE ID:** CVE-2026-59309
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-303
- **Published:** Jul 30, 2026
- **Last Modified:** Jul 30, 2026

## Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

## Affected Products

- VMware — Cloud Foundation (9.1.x.x)
- VMware — Cloud Foundation (9.0.x.x)
- VMware — Cloud Foundation (5.x)
- VMware — vSphere Foundation (9.1.x.x)
- VMware — vSphere Foundation (9.0.x.x)
- VMware — vCenter (9.1.x.x)
- VMware — vCenter (9.0.x.x)
- VMware — vCenter (8.0)
- VMware — Telco Cloud Infrastructure (3.0)
- VMware — Telco Cloud Platform (5.1.x)
- VMware — Telco Cloud Platform (5.0.x)
- VMware — Telco Cloud Platform (4.x)
- VMware — Telco Cloud Platform (3.0)

## References

- [CNA](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 7.94%
- **EPSS Percentile:** 94.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._