VMware vCenter 9.1.0.0300
VMware vCenter 9.1.0.0300 is a critical security update that addresses two severe vCenter vulnerabilities, including an authentication bypass in VMware Directory Service and a directory traversal vulnerability in the vCenter Syslog server that could lead to arbitrary code execution. Both vulnerabilities have a CVSSv3 score of 9.8. Broadcom recommends prompt deployment because no workarounds are available.
- CVE-2026-59309 (CVSS 9.8, Critical): Authentication bypass vulnerability in VMware Directory Service. An attacker with network access to vCenter may bypass authentication and gain unauthorized access to the system.
- CVE-2026-59310 (CVSS 9.8, Critical): Directory traversal vulnerability in the vCenter Syslog server. An attacker with network access may exploit the vulnerability to execute arbitrary code.
- No workarounds are available for these vulnerabilities. Broadcom recommends applying the security update as soon as possible.
What's new
VMware vCenter 9.1.0.0300 is a security-focused update that addresses critical vulnerabilities affecting the vCenter management platform.
Critical Security Fixes- CVE-2026-59309: Resolves a critical authentication bypass vulnerability in VMware Directory Service. A malicious actor with network access to vCenter could exploit the issue to bypass authentication and gain unauthorized access. The vulnerability has a CVSSv3 score of 9.8.
- CVE-2026-59310: Resolves a critical directory traversal vulnerability in the vCenter Syslog server. A malicious actor with network access to vCenter could exploit the issue to execute arbitrary code. The vulnerability has a CVSSv3 score of 9.8.
Broadcom classifies the vulnerabilities addressed by this release as Critical. No workarounds are available, making installation of the security update the recommended remediation.
The update is cumulative. CVE-2026-59309 was initially addressed in vCenter 9.1.0.0200, while vCenter 9.1.0.0300 is the latest available version and includes the previously released fix as well as remediation for CVE-2026-59310.
Operational ImpactUpdating vCenter temporarily interrupts access to the vSphere Client and other vCenter management interfaces. Running virtual machines and containers continue to operate during the vCenter update.
RecommendationOrganizations running affected VMware vCenter 9.1 deployments should prioritize upgrading to version 9.1.0.0300, particularly where vCenter is accessible from broad or untrusted network segments.
๐ฌ Comments (0)
Share any installation issues, compatibility changes, or fixes you noticed.