πŸ”΄ CVE-2026-59310

CVE-2026-59310 is a critical (CVSS 9.8) directory traversal vulnerability in the Syslog server component of VMware vCenter that allows an unauthenticated remote attacker with network access to execute arbitrary code with root-level privileges. This grants direct server compromise of the central virtualization management plane, and it is under active exploitation and listed in CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 β€” Exploit Public-Facing Application
ATT&CK Technique
MEDIUM
Deployment Risk
Yes (+27d)
Ransomware

πŸ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-07-30

Added to CISA KEV: 2026-08-18 19 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

πŸ” Web Intelligence (Kagi Β· 2026-09-14)

Summary

CVE-2026-59310 is a critical directory traversal vulnerability affecting the Syslog server component of VMware vCenter Server. This flaw allows a remote, unauthenticated attacker with network access to the vCenter appliance to manipulate file paths, potentially leading to arbitrary code execution with root-level privileges. Because vCenter is a central management hub for virtualized infrastructure, this vulnerability represents a severe threat to enterprise environments, as successful exploitation can grant an attacker full control over the management plane of an entire data center.

Exploitation

  • Active Exploitation: The vulnerability is under active exploitation in the wild, with reports confirming that threat actors began targeting vulnerable deployments shortly after the disclosure [1][5].
  • Threat Actors: While specific named groups are still being investigated, the speed and scale of exploitation suggest the involvement of sophisticated threat actors targeting critical infrastructure [1].
  • PoC/Exploit Availability: Publicly available proof-of-concept (PoC) code and exploit tools have been identified, significantly lowering the barrier to entry for attackers [2].
  • Prerequisites:
- Network Access: Required (the attacker must have network connectivity to the vCenter server). - Authentication: None required (unauthenticated). - User Interaction: None required. - Attack Vector: Remote, leveraging the Syslog server component.

Affected Products & Patches

  • Affected Versions: VMware vCenter Server versions prior to the patched releases.
  • Patch/Hotfix Availability: Broadcom has released security patches to address this vulnerability. Administrators are advised to update to version 9.1.0.0300 or later, which incorporates the necessary fixes [3].
  • Mitigations: There are no widely recognized workarounds that fully secure the system; patching is the only recommended course of action. If patching is not immediately possible, strict network segmentation to limit access to the vCenter management interface is strongly advised.

Impact

  • Access/Capabilities: Successful exploitation grants an attacker the ability to perform arbitrary directory traversal on the host, which can be leveraged to execute arbitrary code with root-level privileges on the vCenter server [2][4].
  • Business Risk: For internet-facing deployments, this is a "critical" (CVSS 9.8) risk, as it allows attackers to completely compromise the vCenter appliance. This can lead to:
- Complete loss of confidentiality, integrity, and availability for the virtualized environment. - Potential for lateral movement into the underlying ESXi hosts and guest virtual machines. - Massive disruption to business operations and potential exfiltration of sensitive organizational data.

Sources

  1. Attackers Exploit VMware vCenter Vulnerability to Gain ...

    Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings ... The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor…

  2. CVE-2026-59310 VMware vCenter RCE Analysis & Mitigation - Vali Cyber

    Vali Cyber analyzes CVE-2026-59310, a critical VMware vCenter vulnerability enabling unauthenticated root compromise and active attacks.

  3. Support Content Notification - Support Portal - Broadcom support portal

    While CVE-2026-59309 was addressed in 9.1.0.0200 first, version 9.1.0.0300 is the most recent version currently available which includes the fix for this CVE. 3b. vCenter directory-traversal vulnerability (CVE-2026-59310) ... Description: VMware ESX contains an out-of-bounds write vulnerability in t…

  4. NVD-CVE-2026-59310

    CVE-2026-59310 Detail Description VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

  5. CVE-2026-59310 Under Active Exploitation : r/sysadmin

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with... (CVE-2026-59310 Discussion). 3 ...