CVE-2026-59310
Broadcom VMware vCenter Path Traversal Vulnerability
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Description as published by the source, in English.
Key facts
- Published
- 2026-07-30
- Last modified
- 2026-08-19
- Assigned by
- security@vmware.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- security@vmware.com
- Probability of exploitation
-
1.1 %
higher than 63 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-08-18, with a remediation deadline of 2026-08-21 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Vmware | Cloud Foundation | all versions listed | Not affected |
| Vmware | Telco Cloud Infrastructure | 3.0 | Not affected |
| Vmware | Telco Cloud Platform | ≥ 3.0, ≤ 5.2 | Not affected |
| Vmware | Vcenter Server | < 8.0 | Affected |
| Vmware | Vcenter Server | 8.0 | Affected |
| Vmware | Vcenter Server | ≥ 9.0, < 9.0.2.0100 | Affected |
| Vmware | Vcenter Server | ≥ 9.1, < 9.1.0.0300 | Affected |
| Vmware | Vsphere Foundation | all versions listed | Not affected |
Weakness type
-
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special ele…
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/Secu…
- https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across…
- https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
Related at Berigo
Articles
-
Broadcom fixes authentication bypass and code execution in VMware vCenter
Mentions this CVE
2026-07-30
Broadcom published advisory VMSA-2026-0006 on 29 July 2026, fixing five vulnerabilities in VMware vCenter, ESX, Workstation and Fusion. Two of them s…
-
A new backdoor does nothing at all until one crafted packet arrives
Same product
2026-08-25
A new Windows backdoor poses as Microsoft's dpapi.dll and is built to be side-loaded into ESET's ERAAgent.exe. It contacts no fixed server, reading a…
-
Only one of the 91 vulnerabilities Spring patched is rated critical
Same product
2026-08-25
Spring has patched 91 vulnerabilities spread across a range of subprojects, and the advisories on spring.io are dated 20 August. Spring rates one of …
-
Hardcoded credentials in Dell RecoverPoint exploited since 2024
Same product
2026-02-17
Google and Mandiant link UNC6201 to exploitation of CVE-2026-22769 in Dell RecoverPoint for Virtual Machines, used for backdoors and long-term access.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.