After upgrading vCenter Server to address security vulnerabilities (CVE-2026-59309, CVE-2026-59310), VMware Cloud Director (VCD) fails to create new Virtual Machines. The Encryption Management (KMS) solution reports authentication failures when communicating with the vCenter SDK.
On the KMS itself for logs we have errors similar to:time="####-##-## ##:##:##" level=error msg="Post \"https://<vCenter Server>/ext-api/####################/sdk\": 401 Unauthorized\n\tat #################/vcf/vcd-addon-byok/byok/client/vc.(*Client).RetrieveKmipServerStatus(/opt/src/client/vc/crypto.go:139)
Other symptoms may include:
VMware Cloud Director 10.6.1
VMware Cloud Director Encryption Management 1.2.1
vCenter Server 8.0.3
The vCenter upgrade causes a trust mismatch or invalidates the existing session/credentials used by the Encryption Management solution to communicate with the vCenter SDK.
To re-establish trust and resolve the 401 Unauthorized error: