Vulnerability record · CVE-2026-59310 · published 30 July 2026
CVE-2026-59310: VMware vCenter Syslog server path traversal leads to RCE
Vmware · Vcenter Server
VMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary code. The vulnerability is rated CVSS 9.8 critical and is listed in CISA's KEV catalog, making it a high-priority target for defenders.
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote code execution, active exploitation, KEV listing, and known ransomware use make this an urgent patching priority.
What it is
VMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary code. The vulnerability is rated CVSS 9.8 critical and is listed in CISA's KEV catalog, making it a high-priority target for defenders.
Impact
An attacker with network access to vCenter can execute arbitrary code on the appliance, potentially gaining full control of the virtualization management plane. This could lead to compromise of managed hosts, virtual machines, and credential material.
Attack surface
Reachable over the network via the vCenter Syslog server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is required. Any internet-exposed or internally reachable vCenter instance running the affected service is at risk.
Exploitation
CVE-2026-59310 is in CISA's KEV catalog with a due date of 2026-08-21 and is flagged for known ransomware campaign use. EPSS probability is 0.45878 (98.7th percentile), and third-party advisories describe active exploitation across many countries.
What to do
- Apply the vendor patch from Broadcom's security advisory for vCenter Server immediately.
- If patching is not possible, restrict network access to the vCenter Syslog server to trusted management networks only.
- Follow CISA BOD 26-04 guidance, including forensics triage requirements, and consider discontinuing use if mitigations are unavailable.
- Monitor for and block known exploitation indicators associated with this CVE from the referenced third-party advisories.
- Verify vCenter backups and isolate compromised instances before restoring.
Detection
- Review vCenter Syslog server logs for path traversal patterns such as ../ sequences in incoming requests.
- Monitor for unexpected process creation or outbound connections from the vCenter appliance.
- Check for unauthorized changes to vCenter configuration, scheduled tasks, or new administrative accounts.
- Correlate network traffic to vCenter Syslog ports with threat intelligence feeds for CVE-2026-59310 exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-59310 to the Known Exploited Vulnerabilities catalog on 18 August 2026 as "Broadcom VMware vCenter Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 21 August 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-59310 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-59310), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.