CVE-2026-59310

Published Jul 30, 2026

Last updated a month ago

Exploit knownCVSS critical 9.8
VDI
Zero-day
Supply chain
Server
OT
VMware vCenter
Syslog Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-59310 is identified as a directory traversal vulnerability present in the VMware vCenter Syslog server. This flaw enables a remote, unauthenticated attacker with network access to a susceptible vCenter instance to manipulate file and directory paths beyond their intended boundaries. Successful exploitation of this vulnerability can lead to arbitrary code execution on the affected vCenter system. The issue impacts VMware vCenter and other VMware platforms that incorporate the vulnerable vCenter component.

Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Source
security@vmware.com
NVD status
Analyzed
Products
vcenter_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Broadcom VMware vCenter Path Traversal Vulnerability
Exploit added on
Aug 18, 2026
Exploit action due
Aug 21, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security@vmware.com
CWE-22

Social media

Hype score
Not currently trending
  1. VMware vCenter CVE-2026-59310: Babuk Hits 47 Nations A suspected China‑nexus actor exploited CVE‑2026‑59310 in VMware vCenter Server to compromise 361 victim IP… read more → https://t.co/kqrZKU6Dwp #CyberSecurity #InfoSec #GlobalNews

    @aimicyber

    7 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.

    @InfosecDotWatch

    29 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 【技術解説】パッチを待つな、「悪用済み」から塞げ — 8月のCISA KEV追加 CISAが8月、悪用確認済みとしてmacOS画面共有(CVE-2026-65400)、SharePoint(CVE-2026-55040)、VMware vCenter(CVE-2026-59310)をKEVに追加。共通点は「認証の抜

    @iss_kk_official

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-59310 was disclosed July 29. CVSS 9.8, directory traversal in VMware vCenter. Mass exploitation began August 3. Five days. 47 countries, 361 unique attacking IPs. Virtualization management planes were always supposed to be treated as tier zero, alongside domain

    @nik_kale

    29 Aug 2026

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Five days from patch to active exploitation. 47 countries.   Our team traced CVE-2026-59310 to two lines in vCenter's rsyslog config. The syslog service builds ESX log file paths using the hostname from the incoming message and never escapes it. That's enough to write a file int

    @vali_cyber

    27 Aug 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. VMware vCenter : path traversal, exploitation active selon la CISA. Exécution de code via accès réseau. CVE-2026-59310. Exposés ? #CVE #VMware

    @libtracker_io

    25 Aug 2026

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. China-nexus actors breached 361 orgs in 47 countries within five days of the VMware vCenter patch. CVE-2026-59310 is now in CISA KEV at CVSS 9.8. Five days is your whole patch window now. #Cybersecurity #InfoSec #PatchManagement

    @infrasecserv

    23 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 【技術解説】そのランサムウェア、実は"目くらまし"かもしれない ― vCenter を狙うAPTの本当の狙い VMware vCenter の CVE-2026-59310(CVSS

    @iss_kk_official

    23 Aug 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA KEV Aug 18: VMware vCenter path traversal CVE-2026-59310, network attacker to code exec. Scan-now, not a ticket for later.

    @Sirius_Scan

    22 Aug 2026

    57 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550

    @HOCupdate

    21 Aug 2026

    382 Impressions

    2 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824

    @BlackfireLu

    20 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)

    @cyberogz

    20 Aug 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)

    @cyberogz

    20 Aug 2026

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs

    @TheHackersNews

    19 Aug 2026

    48061 Impressions

    90 Retweets

    317 Likes

    91 Bookmarks

    4 Replies

    3 Quotes

  15. CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Aug 18) CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free の脆弱性 CVE-2026-55040 Microsoft SharePoint

    @foxbook

    19 Aug 2026

    278 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日

    @__kokumoto

    18 Aug 2026

    634 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-EDB-AWZes1i ( CVE-2026-48907 ) EGE-GH-86PDTBb ( CVE-2025-55182 ) EGE-GH-uET14Zz ( CVE-2026-20079 ) EGE-GH-voHgFaT ( CVE-2026-59310 ) EGE-GH-seDlYMs ( CVE-2026-59310 ) ..🧵👇

    @exploitgrid

    18 Aug 2026

    88 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. VMware vCenter sotto attacco: due campagne su CVE-2026-59310 e CVE-2026-59309 Guerra Cibernetica, apt, cina, Quirso, vmware https://t.co/70LzXKtk5p https://t.co/2c7vIkMbfb

    @matricedigitale

    17 Aug 2026

    63 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. China-nexus APT is exploiting VMware vCenter CVE-2026-59310 to drop Babuk-derived ransomware, while SAP Commerce Cloud CVE-2026-58231 fell to attackers three days after disclosure. #CyberSecurity #BlueTeam #Ransomware https://t.co/iQq0QuH5Uz

    @itsalreadywhen

    17 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. VMware vCenter sfruttata per accessi SSH dopo la falla CVE-2026-59310 Vulnerabilità, Adobe, LegacyHive zero-day, Sansec, vmware, Windows, Zero-day https://t.co/FRGsDkNgyM https://t.co/sH0eEi36Ce

    @matricedigitale

    17 Aug 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 ZN ALERT | VMware vCenter bajo explotación CVE-2026-59310 | CVSS 9.8 — CRÍTICA Una vulnerabilidad crítica en VMware vCenter Server registra evidencia reciente de explotación real. CVE-2026-59310 corresponde a una vulnerabilidad de directory traversal en el componente

    @ZifraNodeSpa

    16 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2026-59310 (CVSS 9.8) in VMware vCenter: 361 compromised hosts across 47 countries. Suspected APT dropping reverse_ssh via cron for persistence, first beacons 5 days after Broadcom disclosed. No workaround exists. Patching is the only remediation. #InfoSec #ZeroDay #VMware

    @infrasecserv

    15 Aug 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Patch released. Exploitation confirmed after. Attackers now sitting on cron-job persistence + reverse SSH tunnels inside VMware vCenter environments. CVE-2026-59310, CVSS 9.8. If it's in your stack, this isn't a "next sprint" fix. #CyberSecurity #vCenter #SOC #InfoSec https://t

    @Shumailseyar

    15 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2026-59310 VMware vCenter 원격 코드 실행 취약점 원인 분석과 패치 방법 - dailyo https://t.co/Ja45FmVyK5

    @J_zjaan7946

    15 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨VMware vCenterのRCE脆弱性を攻撃者が悪用: CVE-2026-59310 ⚠️Nightmare Eclipse、Windowsのゼロデイエクスプロイト「ShieldBreak」をリリース 🩹マイクロソフト、Nightmare EclipseがリリースしたWindowsゼロデイ「LegacyHive」を

    @MachinaRecord

    14 Aug 2026

    158 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🔒 #CyberSecurity CVE-2026-59310: VMware vCenter Syslog Server RCE Actively Exploited for Reverse… "A critical remote code execution vulnerability in the VMware vCenter Syslog Server — tracked…" 🔗 https://t.co/mUeiLdkAq2 #CyberSecurity #ThreatIntel #critical #zerod

    @SecurityAr58409

    13 Aug 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 CVE-2026-59310 and CVE-2026-65400 are under active exploitation, with CVSS scores of 9.8 and 7.1 respectively. Patch immediately to protect against critical directory traversal and authentication vulnerabilities #ThreatIntel #CyberSecurity https://t.co/h713XbjpvW

    @Npj8448

    13 Aug 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06

    @itsalreadywhen

    12 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. هشدار امنیتی : دسترسی سرور Vmware Esxi و VCenter رو سریعا محدود به آی پی های خودتون کنید. آسیب‌پذیری های بحرانی با شناسه‌های CVE-2026-59309، CVE-2026-59310 و CVE-2026-47876 شناسایی ش

    @alisalehiman

    5 Aug 2026

    3056 Impressions

    2 Retweets

    41 Likes

    20 Bookmarks

    1 Reply

    0 Quotes

  30. CVE-2026-59309 and CVE-2026-59310 let attackers bypass vCenter authentication and gain remote code execution. CVE-2026-47876 lets a malicious VM break out to the ESXi host. Patch now. Full analysis on our blog: https://t.co/1ZxE7H75EZ

    @FSEvolved

    3 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. برای محصولات VMware workstation و ESX و Fusion و vCenter سه آسیب پذیری با کدهای شناسایی CVE-2026-59309 و CVE-2026-59310 و CVE-2026-47876 از نوع authentication bypass و VM escapes منتشر شده است. حتما پچ و به رو

    @EthicalSafe

    1 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Warning: A critical incorrect authentication vulnerability and a path traversal vulnerability in #Broadcom #VMware #vCenter #CVE-2026-59309 #CVE-2026-59310 CVSS: 9.8 An unauthorized remote attacker can exploit them to execute arbitrary code #Patch #Patch #Patch

    @CCBalert

    31 Jul 2026

    283 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Kritické zranitelnosti v produktech VMware: CVE-2026-59309, CVE-2026-59310 a CVE-2026-47876 https://t.co/vXshekv7r8

    @abclinuxu

    31 Jul 2026

    107 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 CRITICAL VMware Alert – PATCH NOW! VMSA-2026-0006: CVSS 9.8 auth bypass + RCE in vCenter. No workarounds. Broadcom dropped the bombshell on July 29. Two critical flaws (CVE-2026-59309 & CVE-2026-59310) let attackers bypass login and execute code with network access

    @CyberAlert_

    31 Jul 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. 🚨 Upozorňujeme na kritické zranitelnosti v produktech VMware, CVE-2026-59309, CVE-2026-59310 a CVE-2026-47876. Zranitelnosti v VMware vCenter umožňují vzdálenému útočníkovi se síťovým přístupem obejít autentizaci a získat neoprávněný přístup k vCenter, p

    @GOVCERT_CZ

    31 Jul 2026

    650 Impressions

    3 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    1 Quote

  36. Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden. https://t.co/JefXtYbpy2

    @etguenni

    31 Jul 2026

    337 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  37. VMware vCenterに認証回避とRCEの脆弱性、CVE-2026-59309とCVE-2026-59310はCVSS 9.8 https://t.co/SEYY8Vtgbq #セキュリティ対策Lab #security #securitynews #脆弱性

    @securityLab_jp

    31 Jul 2026

    166 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  38. Broadcom patched five VMware vulnerabilities across vCenter, ESX, Workstation, and Fusion, three of them critical. Two vCenter flaws (CVE-2026-59309, an auth bypass, and CVE-2026-59310, a directory traversal enabling code execution) score 9.8, while a VMXNET3 out-of-bounds write

    @CyberAlertsHQ

    30 Jul 2026

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. ⚡️ VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow control of entir

    @zerodayalpha

    30 Jul 2026

    6652 Impressions

    11 Retweets

    65 Likes

    25 Bookmarks

    2 Replies

    2 Quotes

  40. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://t.co/d4U3b5FBIT

    @autumn_good_35

    30 Jul 2026

    739 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  41. ⚠️ Vulnerabilidades en productos VMware ❗ CVE-2026-59310 ❗ CVE-2026-59309 ❗ CVE-2026-47876 ➡️ Más info: https://t.co/oLyx4EA1TW https://t.co/ENzqZOx4NN

    @CERTpy

    30 Jul 2026

    173 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  42. Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) https://t.co/XY9zKzJGdN

    @ReneRobichaud

    30 Jul 2026

    88 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) https://t.co/RmLeDd9yX1

    @CeptBiro

    30 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🚨 On 7/29/26, #Broadcom published a security advisory addressing multiple vulns in #VMWare products. Of particular interest are CVE-2026-59309 & CVE-2026-59310, 2 critical, remotely exploitable vulns affecting vCenter Server. More in the Rapid7 blog: https://t.co/G0QjsUI

    @rapid7

    30 Jul 2026

    3247 Impressions

    10 Retweets

    25 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨 ALERTĂ - Vulnerabilități critice în VMware ➡️ Broadcom a publicat în cadrul buletinului VMSA-2026-0006 actualizări care remediază mai multe vulnerabilități din produsele VMware. ⚠️ CVE-2026-59309 ⚠️ CVE-2026-59310 ⚠️ CVE-2026-47876 👉 https://

    @DNSC_RO

    30 Jul 2026

    177 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. JUST IN: Broadcom patches critical VMware vCenter flaws (CVE-2026-59309 & CVE-2026-59310, both CVSS 9.8). Remote unauthenticated attackers can bypass authentication or achieve remote code execution. A separate critical VM escape vulnerability also affects ESXi. No workarounds

    @CyberWatch05

    30 Jul 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Two CVSS 9.8s just hit VMware vCenter (VMSA-2026-0006): • CVE-2026-59309 — auth bypass (network) • CVE-2026-59310 — RCE via path traversal + a VM-escape in ESX No in-the-wild exploitation yet. Patch now. The finding is the CVE. The exposure is your control plane. https

    @fiks_cloud

    30 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  48. CVE-2026-59309/CVE-2026-59310 CVSS9.8という非常にクリティカルであるとういう情報もネットには出ています。 【セキュリティ ニュース】「#VMware #ESX」「VMware #vCenter」に深刻な #脆弱性 - 修正版が公開(1ページ目 / 全2

    @anzendo

    30 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. VMwareが多数の脆弱性を修正(VMSA-2026-0006)。重大(Critical)な脆弱性として、vCenterの遠隔コード実行CVE-2026-59309及びCVE-2026-59310と、ESXiのVMエスケープCVE-2026-47876が含まれている。境界外書き込みのCVE-2026-41703はESXiのほ

    @__kokumoto

    29 Jul 2026

    647 Impressions

    1 Retweet

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  50. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) https://t.co/WmqO1KgmBJ

    @makopicut

    29 Jul 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations