Hackers Intensify Scans for VMware vCenter Vulnerabilities

Recent reports indicate a surge in scanning activities targeting VMware vCenter servers, following the disclosure of critical vulnerabilities. Security researchers have observed increased attempts to identify exposed vCenter systems, particularly through requests to the /sdk/ endpoint and the /websso single sign-on path. While these scans do not confirm successful breaches, they signify that attackers are actively seeking vulnerable systems to exploit.

This uptick in scanning activity comes in the wake of Broadcom’s security advisory VMSA-2026-0006, released on July 29, 2026. The advisory details five vulnerabilities affecting VMware products, including vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products. Among these, three vulnerabilities have been rated as critical.

Critical Vulnerabilities in VMware vCenter

The most pressing concern for vCenter administrators is CVE-2026-59309, an authentication bypass flaw in the VMware Directory Service (vmdir) with a CVSS score of 9.8. This vulnerability allows a remote attacker with network access to bypass authentication mechanisms and gain unauthorized access to the vCenter environment. Such access could enable attackers to alter virtual machine configurations, create new accounts, modify network settings, access sensitive data, disrupt workloads, or further infiltrate the organization’s network.

Another critical vulnerability, CVE-2026-59310, involves a directory traversal issue in the vCenter Syslog Server. This flaw could permit network-based attackers to execute arbitrary code on the affected system. Additionally, CVE-2026-47876 affects the VMXNET3 virtual network adapter in ESXi, potentially allowing a malicious virtual machine user to execute code on the underlying host.

Implications and Recommended Actions

The management plane of vCenter servers often contains credentials, host details, backups, and information about critical business systems. Consequently, any compromise of vCenter poses significant risks to organizations operating virtual environments. The observed scanning activities should serve as an early warning, emphasizing the need for immediate action.

Administrators are urged to identify all vCenter systems within their networks and assess their exposure to untrusted networks. Broadcom has released patches addressing these vulnerabilities, including vCenter 8.0 U3k, VMware Cloud Foundation and vSphere Foundation 9.0.2.0100, and version 9.1.0.0300. Organizations should prioritize testing and deploying these updates promptly, as no known workarounds can effectively mitigate these vulnerabilities.

Furthermore, security teams should monitor logs for unusual requests to the /sdk/ and /websso/ endpoints, investigate unexpected authentication events, new account creations, permission changes, suspicious virtual machine activities, and unfamiliar management connections. Implementing measures such as restricting vCenter access to authorized administrator networks, enforcing multifactor authentication, and isolating management services can further reduce the risk of exploitation.

Given the critical nature of these vulnerabilities and the active scanning by potential attackers, organizations must act swiftly to secure their VMware vCenter environments. Proactive patching and vigilant monitoring are essential to prevent unauthorized access and potential breaches.