CVE-2026-59310

Published Jul 30, 2026

Last updated a day ago

CVSS critical 9.8
VMware vCenter
Syslog Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-59310 is identified as a directory traversal vulnerability present in the VMware vCenter Syslog server. This flaw enables a remote, unauthenticated attacker with network access to a susceptible vCenter instance to manipulate file and directory paths beyond their intended boundaries. Successful exploitation of this vulnerability can lead to arbitrary code execution on the affected vCenter system. The issue impacts VMware vCenter and other VMware platforms that incorporate the vulnerable vCenter component.

Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Source
security@vmware.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@vmware.com
CWE-22

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

17

  1. Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden. https://t.co/JefXtYbpy2

    @etguenni

    31 Jul 2026

    228 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Broadcom patched five VMware vulnerabilities across vCenter, ESX, Workstation, and Fusion, three of them critical. Two vCenter flaws (CVE-2026-59309, an auth bypass, and CVE-2026-59310, a directory traversal enabling code execution) score 9.8, while a VMXNET3 out-of-bounds write

    @CyberAlertsHQ

    30 Jul 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚡️ VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow control of entir

    @zerodayalpha

    30 Jul 2026

    6652 Impressions

    11 Retweets

    65 Likes

    25 Bookmarks

    2 Replies

    2 Quotes

  4. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://t.co/d4U3b5FBIT

    @autumn_good_35

    30 Jul 2026

    739 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  5. ⚠️ Vulnerabilidades en productos VMware ❗ CVE-2026-59310 ❗ CVE-2026-59309 ❗ CVE-2026-47876 ➡️ Más info: https://t.co/oLyx4EA1TW https://t.co/ENzqZOx4NN

    @CERTpy

    30 Jul 2026

    173 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) https://t.co/XY9zKzJGdN

    @ReneRobichaud

    30 Jul 2026

    88 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) https://t.co/RmLeDd9yX1

    @CeptBiro

    30 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 On 7/29/26, #Broadcom published a security advisory addressing multiple vulns in #VMWare products. Of particular interest are CVE-2026-59309 & CVE-2026-59310, 2 critical, remotely exploitable vulns affecting vCenter Server. More in the Rapid7 blog: https://t.co/G0QjsUI

    @rapid7

    30 Jul 2026

    3247 Impressions

    10 Retweets

    25 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 ALERTĂ - Vulnerabilități critice în VMware ➡️ Broadcom a publicat în cadrul buletinului VMSA-2026-0006 actualizări care remediază mai multe vulnerabilități din produsele VMware. ⚠️ CVE-2026-59309 ⚠️ CVE-2026-59310 ⚠️ CVE-2026-47876 👉 https://

    @DNSC_RO

    30 Jul 2026

    177 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. JUST IN: Broadcom patches critical VMware vCenter flaws (CVE-2026-59309 & CVE-2026-59310, both CVSS 9.8). Remote unauthenticated attackers can bypass authentication or achieve remote code execution. A separate critical VM escape vulnerability also affects ESXi. No workarounds

    @CyberWatch05

    30 Jul 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Two CVSS 9.8s just hit VMware vCenter (VMSA-2026-0006): • CVE-2026-59309 — auth bypass (network) • CVE-2026-59310 — RCE via path traversal + a VM-escape in ESX No in-the-wild exploitation yet. Patch now. The finding is the CVE. The exposure is your control plane. https

    @fiks_cloud

    30 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. CVE-2026-59309/CVE-2026-59310 CVSS9.8という非常にクリティカルであるとういう情報もネットには出ています。 【セキュリティ ニュース】「#VMware #ESX」「VMware #vCenter」に深刻な #脆弱性 - 修正版が公開(1ページ目 / 全2

    @anzendo

    30 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. VMwareが多数の脆弱性を修正(VMSA-2026-0006)。重大(Critical)な脆弱性として、vCenterの遠隔コード実行CVE-2026-59309及びCVE-2026-59310と、ESXiのVMエスケープCVE-2026-47876が含まれている。境界外書き込みのCVE-2026-41703はESXiのほ

    @__kokumoto

    29 Jul 2026

    647 Impressions

    1 Retweet

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  14. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://t.co/WmqO1KgmBJ

    @makopicut

    29 Jul 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. Broadcom issued VMSA-2026-0006 fixing five vulnerabilities in VMware vCenter and ESX, two rated Critical. CVE-2026-59309 allows network authentication bypass in VMware Directory Service. CVE-2026-59310 enables path traversal leading to code execution via Syslog processing.

    @WorldCyberNewsX

    29 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Attackers chained three critical VMware vulnerabilities to escalate from vCenter authentication bypass to ESX host compromise. CVE-2026-59309 and CVE-2026-59310 enabled initial access and code execution, while CVE-2026-47876 allowed VM escape for lateral movement. Runtime

    @aviatrixtrc

    29 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CRITICAL: Three new VMware flaws patch today auth bypass in vCenter (CVE-2026-59309), RCE via directory traversal (CVE-2026-59310), and VM escape in VMXNET3 (CVE-2026-47876). No active exploitation yet. Update ESXi/vCenter now. https://t.co/SNQLvS4va8 #infosec #cve #vmware

    @staatse_sec

    29 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Broadcom patched three critical VMware flaws across ESX, vCenter, Workstation, and Fusion. Two hit vCenter at CVSS 9.8: an authentication bypass (CVE-2026-59309) and a directory traversal enabling remote code execution (CVE-2026-59310). A third, CVSS 9.3, lets a VM with local

    @XavierRiveraX

    29 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. VMware vCenterのCVE-2026-59309およびCVE-2026-59310、CVSS 9.8の深刻度に https://t.co/wLtXSfJIKo

    @TYOBlackHatNews

    29 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution. #VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec https://t.co/pL0q1pY7eU

    @Daily_CyberSec

    29 Jul 2026

    352 Impressions

    3 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 5 VMware flaws just patched by Broadcom (ESXi, vCenter, Workstation, Fusion): 🔴 Critical: CVE-2026-47876 – VM escape via VMXNET3 adapter CVE-2026-59309 – vCenter auth bypass CVE-2026-59310 – vCenter RCE 🟠 High: CVE-2026-41703 – DoS/info leak 🟡 Low: CVE-20

    @techepages

    29 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched. #VMware #CyberSecurity #CVE202659309 #InfoSec https://t.co/s0wVPTJyDN

    @Daily_CyberSec

    29 Jul 2026

    303 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes