> ## Content Index
> Fetch the complete content index at: https://intelligence.zerodayengineering.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# ⚡️ 0-Day Alert: VMware ESXi + vCenter
- URL: https://intelligence.zerodayengineering.com/0-day-alert-cve-2026-59309/
- Published: 2026-07-30T16:44:40.000Z
- Updated: 2026-09-18T12:51:10.000Z
- Description: VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors.
- Author: Zero Day Engineering
- Tags: 0-Day Alerts

VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). 

Two attack vectors: 

1\. Remote attack on vCenter –

CVE-2026-59309: auth bypass via network access

CVE-2026-59310: directory traversal RCE

An exploit would allow control of entire ESXi infrastructure.

2\. A VM-escapable set of two bugs –

CVE-2026-59310: vmxnet3 OOBW

CVE-2026-41703: core OOBR

These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.

Diffing and exploiting (1) is straightforward and should be patched promptly.