CVE-2026-59310 is a critical (CVSS 9.8) directory traversal vulnerability in the Syslog server component of VMware vCenter that allows an unauthenticated remote attacker with network access to execute arbitrary code with root-level privileges. This grants direct server compromise of the central virtualization management plane, and it is under active exploitation and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-07-30
Added to CISA KEV: 2026-08-18 19 DAYS BETWEEN CVE AND KEV
CVE-2026-59310 is a critical directory traversal vulnerability affecting the Syslog server component of VMware vCenter Server. This flaw allows a remote, unauthenticated attacker with network access to the vCenter appliance to manipulate file paths, potentially leading to arbitrary code execution with root-level privileges. Because vCenter is a central management hub for virtualized infrastructure, this vulnerability represents a severe threat to enterprise environments, as successful exploitation can grant an attacker full control over the management plane of an entire data center.
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings ... The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actorβ¦
Vali Cyber analyzes CVE-2026-59310, a critical VMware vCenter vulnerability enabling unauthenticated root compromise and active attacks.
While CVE-2026-59309 was addressed in 9.1.0.0200 first, version 9.1.0.0300 is the most recent version currently available which includes the fix for this CVE. 3b. vCenter directory-traversal vulnerability (CVE-2026-59310) ... Description: VMware ESX contains an out-of-bounds write vulnerability in tβ¦
CVE-2026-59310 Detail Description VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with... (CVE-2026-59310 Discussion). 3 ...