VC

VMware vCenter 9.1.0.0300

Get release alerts
9.1.0.0200โ†’9.1.0.0300SecurityEmergencyBug fix
๐Ÿ“… July 29, 2026๐Ÿ—‚ Virtualization๐Ÿ“ฆ VMware vCenter โ†—๐Ÿ“œ Full changelog โ†—
โœฆ Editor's summary

VMware vCenter 9.1.0.0300 is a critical security update that addresses two severe vCenter vulnerabilities, including an authentication bypass in VMware Directory Service and a directory traversal vulnerability in the vCenter Syslog server that could lead to arbitrary code execution. Both vulnerabilities have a CVSSv3 score of 9.8. Broadcom recommends prompt deployment because no workarounds are available.

โš  Security impact
  • CVE-2026-59309 (CVSS 9.8, Critical): Authentication bypass vulnerability in VMware Directory Service. An attacker with network access to vCenter may bypass authentication and gain unauthorized access to the system.
  • CVE-2026-59310 (CVSS 9.8, Critical): Directory traversal vulnerability in the vCenter Syslog server. An attacker with network access may exploit the vulnerability to execute arbitrary code.
  • No workarounds are available for these vulnerabilities. Broadcom recommends applying the security update as soon as possible.

What's new

VMware vCenter 9.1.0.0300 is a security-focused update that addresses critical vulnerabilities affecting the vCenter management platform.

Critical Security Fixes
  • CVE-2026-59309: Resolves a critical authentication bypass vulnerability in VMware Directory Service. A malicious actor with network access to vCenter could exploit the issue to bypass authentication and gain unauthorized access. The vulnerability has a CVSSv3 score of 9.8.
  • CVE-2026-59310: Resolves a critical directory traversal vulnerability in the vCenter Syslog server. A malicious actor with network access to vCenter could exploit the issue to execute arbitrary code. The vulnerability has a CVSSv3 score of 9.8.
Security Update Guidance

Broadcom classifies the vulnerabilities addressed by this release as Critical. No workarounds are available, making installation of the security update the recommended remediation.

The update is cumulative. CVE-2026-59309 was initially addressed in vCenter 9.1.0.0200, while vCenter 9.1.0.0300 is the latest available version and includes the previously released fix as well as remediation for CVE-2026-59310.

Operational Impact

Updating vCenter temporarily interrupts access to the vSphere Client and other vCenter management interfaces. Running virtual machines and containers continue to operate during the vCenter update.

Recommendation

Organizations running affected VMware vCenter 9.1 deployments should prioritize upgrading to version 9.1.0.0300, particularly where vCenter is accessible from broad or untrusted network segments.

More from VMware vCenter
VMware vCenter 9.1.0.0200SecurityBug fixPerformanceJul 13, 2026
Latest in Virtualization
VirtualBox: VirtualBox 7.2.14Bug fixPerformanceJul 21, 2026
VirtualBox: VirtualBox 7.2.12Bug fixPerformanceJun 30, 2026
Proxmox VE: Proxmox VE 9.2FeatureBug fixPerformanceMay 21, 2026

๐Ÿ’ฌ Comments (0)

Have you installed this VMware vCenter update?

Share any installation issues, compatibility changes, or fixes you noticed.