
vCenter pre-auth RCE: CVE-2026-59309/59310
vCenterVMwareRCECVEauthentication bypasspath traversalremote code executionvulnerabilitysecurity
Two pre-authentication vulnerabilities have been discovered in VMware vCenter through patch-diffing, identified as CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities are rated 9.8 in severity. The first is an authentication bypass, and the second is a syslog path traversal vulnerability that leads to remote code execution.