INCIBE warns on 5 critical VMware flaws
INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.
INCIBE-CERT issued early warning alert INCIBE-2026-518 on Thursday, July 30, 2026, focused on five vulnerabilities in VMware products. Three are rated critical and can enable remote code execution and unauthorized access, according to VMware bulletin VMSA-2026-0006.
VMware alerts and a vCenter flaw
Spain's INCIBE-CERT issued early warning notice INCIBE-2026-518 on Thursday, July 30, 2026. The agency warned about five vulnerabilities in VMware products, three of them classified as critical and capable of enabling remote code execution and unauthorized access.
The notice is based on VMware bulletin VMSA-2026-0006. Among that set, vulnerability CVE-2026-59309 allows an attacker with network access to vCenter to bypass authentication and gain unauthorized access to the affected system.
The combination of remote access, authentication bypass and the potential for code execution places these flaws in a category that calls for immediate attention in environments that manage virtualized infrastructure.
Remote access risk in the region
Alongside that notice, CISA's KEV includes CVE-2026-0257 in Palo Alto Networks' PAN-OS. The vulnerability affects authentication and allows unauthorized VPN connections. CISA says active exploitation has already been observed, and Internet-exposed remote access devices should be patched as a priority.
That has direct implications for Latin American organizations that rely on PAN-OS to provide secure access for remote workers. In those deployments, a flaw in the authentication layer can open the door to unauthorized connections through exposed services.
Correlation with regional technical alerts
The picture left by these alerts is consistent with the monitoring work also reflected in regional technical bulletins such as those from Ciberplaneta, which include CVE-2026-45247, CVE-2026-0257, CVE-2024-21182 and CVE-2022-0492 in their cybersecurity bulletins, alerts and IOCs.
In parallel, the available material also points to CERT-FR advisories for Palo Alto Networks, Juniper Networks, Traefik and Wireshark products, as well as VMware advisories. For security teams and administrators, the immediate focus is identifying exposure, prioritizing patching and checking whether remote access devices are published on the Internet.
Sources
- INCIBE-CERT alerta de tres vulnerabilidades críticas VMwaremoncloa.com· Moncloa.com
- Vulnerabilidades (sección de alerta temprana de INCIBE-CERT)incibe.es· INCIBE-CERT
- Avis de sécurité CERTFR-2026-AVI-0853 (Palo Alto Networks)cert.ssi.gouv.fr· CERT-FR / ANSSI
- Avis de sécurité CERTFR-2026-AVI-0852 (Juniper Networks)cert.ssi.gouv.fr· CERT-FR / ANSSI
- Avis de sécurité CERTFR-2026-AVI-0851 (Traefik)cert.ssi.gouv.fr· CERT-FR / ANSSI
- Avis de sécurité CERTFR-2026-AVI-0849 (Wireshark)cert.ssi.gouv.fr· CERT-FR / ANSSI
- Boletines de Ciberseguridad - Alertas y IOC (varios CVE, incluyendo CVE-2026-45247, CVE-2026-0257, CVE-2024-21182, CVE-2022-0492)ciberplaneta.org· Ciberplaneta
- Avis CERTFR-2026-AVI-0853 – Vulnérabilités dans des produits Palo Alto Networkscert.ssi.gouv.fr· ANSSI / CERT-FR
- Avis CERTFR-2026-AVI-0852 – Vulnérabilités dans des produits Juniper Networkscert.ssi.gouv.fr· ANSSI / CERT-FR
- Avis CERTFR-2026-AVI-0851 – Vulnérabilités dans Traefikcert.ssi.gouv.fr· ANSSI / CERT-FR
- Avis CERTFR-2026-AVI-0849 – Vulnérabilités dans Wiresharkcert.ssi.gouv.fr· ANSSI / CERT-FR
- Known Exploited Vulnerabilities (KEV) Catalogcisa.gov· CISA
- Oracle Critical Patch Update Advisory - January 2024oracle.com· Oracle
- CVE-2022-0492 – Linux kernel cgroups v1 release_agent privilege escalationaccess.redhat.com· MITRE / Red Hat



