Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
Key Takeaways Threat actors are actively scanning for VMware vCenter systems vulnerable to recently disclosed critical flaws. The most severe vulnerability, CVE-2026-59309, is an authentication...
Key Takeaways
- Threat actors are actively scanning for VMware vCenter systems vulnerable to recently disclosed critical flaws.
- The most severe vulnerability, CVE-2026-59309, is an authentication bypass in VMware Directory Service (vmdir) with a CVSS score of 9.8.
- Successful exploitation could grant attackers unauthorized access to vCenter environments, posing a significant risk to virtualized infrastructures.
- Broadcom released patches on July 29, and immediate application of these updates is crucial.
Cybersecurity researchers are observing a surge in scanning activity targeting VMware vCenter deployments following the disclosure of multiple critical vulnerabilities. Honeypots operated by DefusedCyber have recorded an increase in fingerprinting attempts, specifically requests to the /sdk/ endpoint utilizing RetrieveServiceContent and exploration of the /websso single sign-on path.
Table Of Content
While these requests do not definitively indicate a successful compromise, they strongly suggest that malicious actors are actively identifying exposed systems as a precursor to launching more direct and targeted attacks.
This heightened activity comes on the heels of Broadcom’s VMSA-2026-0006 security advisory, issued on July 29. The advisory detailed five vulnerabilities impacting various VMware products, including vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products.
Critical Vulnerabilities Identified
Among the disclosed flaws, three received critical severity ratings. The most pressing concern for vCenter administrators is CVE-2026-59309, an authentication bypass vulnerability found within the VMware Directory Service (vmdir). This flaw carries a CVSS score of 9.8, indicating its extreme severity.
A remote attacker with network access could exploit CVE-2026-59309 to bypass standard authentication mechanisms and gain unauthorized entry into the vCenter environment. Given that vCenter serves as the central management plane for virtual infrastructure, it represents a highly valuable target. Compromise of vCenter could allow an attacker to manipulate virtual machine settings, create new accounts, alter network configurations, access virtual disks, disrupt workloads, and potentially expand their foothold deeper into an organization’s network.
The management plane often contains sensitive data, including credentials, host details, backups, and critical business system information, making its exposure particularly dangerous for organizations relying on virtualized environments.
DefusedCyber also highlighted on X another critical vulnerability, CVE-2026-59310, a directory traversal flaw in the vCenter Syslog Server. This vulnerability could enable network-based attackers to execute arbitrary code on affected systems.
A third critical issue, CVE-2026-47876, impacts the VMXNET3 virtual network adapter in ESXi. This flaw could potentially allow a malicious user of a virtual machine to execute code on the underlying host operating system.
Collectively, these vulnerabilities offer attackers multiple avenues to compromise sensitive management infrastructure. At the time of the advisory’s publication, there were no public proof-of-concept exploits or confirmed instances of exploitation. Therefore, the current scanning activity should be interpreted as an early warning sign, rather than definitive confirmation of active exploitation for CVE-2026-59309 or other flaws.
It is common for scanning to commence shortly after critical vulnerability disclosures, as automated systems begin searching for susceptible targets. Security teams are strongly advised against waiting for public exploit code to emerge before taking action.
What You Should Do
- Immediately identify all VMware vCenter systems within your environment.
- Assess whether any vCenter instances are exposed to untrusted networks.
- Apply the relevant security updates provided by Broadcom without delay. Fixed releases include vCenter 8.0 U3k, VMware Cloud Foundation and vSphere Foundation 9.0.2.0100, and version 9.1.0.0300.
- Review web, reverse proxy, firewall, and vCenter logs for any unusual requests to
/sdk/and/websso/. - Investigate unexpected authentication events, newly created accounts, permission changes, suspicious virtual machine activity, and unfamiliar management connections.
- Restrict vCenter access to approved administrator networks and enforce multifactor authentication (MFA) for all management interfaces.
- Isolate management services to reduce their exposure to potential threats.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.