2026-08-20 【漏洞預警】Broadcom VMware vCenter存在多項重大漏洞(CVE-2026-59309、CVE-2026-59310)遭利用,請評估進行修補作業

 

內容說明:

一、 Broadcom近期發布安全公告,指出其VMware vCenter存在多項資安漏洞,相關重大漏洞說明如下:

1. CVE-2026-59309:VMware Directory Service存在身分驗證繞過(Authentication Bypass)漏洞,具vCenter網路存取權限的攻擊者可利用此漏洞繞過身分驗證,進而未經授權存取系統。

2. CVE-2026-59310:Syslog伺服器存在目錄遍歷(Directory Traversal)漏洞,具vCenter網路存取權限的攻擊者可利用此漏洞執行任意程式碼。

二、已揭露攻擊活動說明 [2][3][4] 1. CISA已將CVE-2026-59310納入漏洞利用清單。

2. 資安公司QUIRSO於事件調查中發現CVE-2026-59310遭主動利用,已識別361個受影響系統IP位址,分布於47個國家。

3. QUIRSO另觀察到疑似與CVE-2026-59309相關之攻擊活動,包括建立vCenter管理者帳號,以及透過vSphere REST API列舉虛擬機器、主機及網路等資訊。

 

影響平台:

1. VMware Cloud Foundation / VMware vSphere Foundation(vCenter元件)9.1.x.x系列版本受影響,建議升級至9.1.0.0300或以上版本。

2. VMware Cloud Foundation / VMware vSphere Foundation(vCenter元件)9.0.x.x系列版本受影響,建議升級至9.0.2.0100或以上版本。

3. VMware vCenter 8.0版本受影響,建議依使用版本升級至8.0 U3k或8.0 U2f版本。

4. VMware vCenter 7.0版本受影響,該版本已終止支援(EOS);如已簽訂延伸支援合約,請洽原廠技術支援。

5. VMware Cloud Foundation(vCenter元件)5.x系列版本受影響,建議依官方公告套用非同步修補(Async Patch)更新至8.0 U3k版本,詳見修補指引KB88287。

6. VMware Telco Cloud Platform(vCenter元件)3.0、4.x、5.0.x及5.1.x系列版本受影響,建議依Broadcom KB449886進行修補。

7. VMware Telco Cloud Infrastructure(vCenter元件)3.0版本受影響,建議依Broadcom KB449886進行修補。

 

解決辦法:官方已發布修補程式,建議依據單位內漏洞管理機制進行相關作業。

 

參考資料:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d

https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff