Vulnerabilities

CVE-2026-59310

Broadcom VMware vCenter Path Traversal Vulnerability

Actively exploited (CISA KEV) Critical 9.8 CVSS 3.1

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Description as published by the source, in English.

Key facts

Published
2026-07-30
Last modified
2026-08-19
Assigned by
security@vmware.com
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored by
security@vmware.com
Probability of exploitation
1.1 % higher than 63 % of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-08-18, with a remediation deadline of 2026-08-21 for US federal agencies.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected products

Vendor Product Versions Status
Vmware Cloud Foundation all versions listed Not affected
Vmware Telco Cloud Infrastructure 3.0 Not affected
Vmware Telco Cloud Platform ≥ 3.0, ≤ 5.2 Not affected
Vmware Vcenter Server < 8.0 Affected
Vmware Vcenter Server 8.0 Affected
Vmware Vcenter Server ≥ 9.0, < 9.0.2.0100 Affected
Vmware Vcenter Server ≥ 9.1, < 9.1.0.0300 Affected
Vmware Vsphere Foundation all versions listed Not affected

Weakness type

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities