Column 1
Skip to content

VMware vCenter CVE-2026-59310: Patch VMSA-2026-0006 Now

August 20, 2026

VMware vCenter administrators should prioritize the Broadcom update path for VMSA-2026-0006 now. CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog on August 18, 2026. Broadcom rates this vCenter issue critical and states that there is no workaround.

This is a defensive maintenance guide for the vCenter management plane. It does not include attack instructions. For the exact product path, use the current Broadcom VMSA-2026-0006 advisory and confirm each environment before making a change.

What Needs Attention

Broadcom’s advisory covers several VMware products. For vCenter, it addresses CVE-2026-59310 alongside CVE-2026-59309. CISA’s KEV entry applies to CVE-2026-59310, so administrators should treat internet-reachable and broadly reachable management services as a priority.

Choose the Supported Update Path

Broadcom’s response matrix lists the following fixed versions for the affected vCenter tracks. The matrix is the source of truth and should be rechecked immediately before maintenance.

  • VCF or vSphere Foundation vCenter 9.1: move to 9.1.0.0300 or later.
  • VCF or vSphere Foundation vCenter 9.0: move to 9.0.2.0100 or later.
  • vCenter 8.0: use the applicable 8.0 U3k or 8.0 U2f fixed track shown in the advisory.
  • vCenter 7.0: contact Broadcom if your organization has an extended-support contract; do not assume a current patch is available.
  • VCF 5.x: follow Broadcom’s documented async patch path rather than applying an ad hoc upgrade.

Plan the Maintenance Window

  1. Inventory every vCenter appliance, its product family, release track, and management-network exposure.
  2. Read the advisory, release notes, compatibility guidance, and product-specific matrix for that exact release before scheduling work.
  3. Confirm a tested recovery plan and that the team knows the rollback limits before changing the management plane.
  4. Coordinate cluster, backup, monitoring, and application owners so maintenance mode, workload movement, and expected service effects are understood.
  5. Restrict unnecessary access to vCenter while the window is being prepared. Keep management interfaces separate from public-facing application traffic.

Verify After the Update

  • Confirm the appliance reports the intended supported build and that the inventory is complete.
  • Check that vCenter login, inventory, host connectivity, alarms, and approved backup integration behave normally.
  • Review management-plane health and recent administrative activity for signs that need incident-response follow-up.
  • Record the advisory, maintenance window, resulting version, and any follow-up work in the change record.

Keep the Virtualization Runbook Current

Use this update as a reason to review maintenance sequencing, access boundaries, and recovery expectations. For related planning, see our VMware and Broadcom hosting checklist and WordPress support when virtual infrastructure also supports client websites.

Sources