CiberLATAMbywhalemate

INCIBE warns on 5 critical VMware flaws

INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

INCIBE-CERT issued early warning alert INCIBE-2026-518 on Thursday, July 30, 2026, focused on five vulnerabilities in VMware products. Three are rated critical and can enable remote code execution and unauthorized access, according to VMware bulletin VMSA-2026-0006.

Spain's INCIBE-CERT issued early warning notice INCIBE-2026-518 on Thursday, July 30, 2026, warning about five vulnerabilities in VMware products. Three are rated critical and can allow remote code execution and unauthorized access. The notice is based on VMware bulletin VMSA-2026-0006.

What specific vulnerability does VMware's advisory highlight?

CVE-2026-59309 allows an attacker with network access to vCenter to bypass authentication and gain unauthorized access to the affected system, according to VMware bulletin VMSA-2026-0006. The combination of remote access, authentication bypass, and possible code execution places these flaws in a category that needs immediate attention in environments that manage virtualized infrastructure.

What other technical alerts appear alongside it?

Alongside that notice, CISA's KEV includes CVE-2026-0257 in Palo Alto Networks' PAN-OS and says active exploitation has already been observed, with Internet-exposed remote access devices needing priority patching. The vulnerability affects authentication and allows unauthorized VPN connections.

That has direct implications for Latin American organizations that rely on PAN-OS to provide secure access for remote workers. In those deployments, a flaw in the authentication layer can open the door to improper connections through exposed services.

How does this relate to other regional alerts?

The picture left by these alerts is consistent with the monitoring work reflected in regional technical bulletins such as Ciberplaneta's, which include CVE-2026-45247, CVE-2026-0257, CVE-2024-21182 and CVE-2022-0492 in their cybersecurity bulletins, alerts and IOCs.

The available material also points to CERT-FR advisories for Palo Alto Networks, Juniper Networks, Traefik and Wireshark products, along with VMware advisories. For security teams and administrators, the immediate focus is on identifying exposure, prioritizing patching and checking whether remote access devices are published on the Internet.

Sources

View all