← Vulnerability feed

Vulnerability record · CVE-2026-59310 · published 30 July 2026

CVE-2026-59310: VMware vCenter Syslog server path traversal leads to RCE

Vmware · Vcenter Server

VMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary code. The vulnerability is rated CVSS 9.8 critical and is listed in CISA's KEV catalog, making it a high-priority target for defenders.

9.8 CVSS 3.1 Critical CISA KEV since 18 Aug 2026 Known ransomware use EPSS 2.6% · top 15.5% CWE-22 · Path traversal
9.8CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
19 Aug 2026Last modified by NVD

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, active exploitation, KEV listing, and known ransomware use make this an urgent patching priority.

What it is

VMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary code. The vulnerability is rated CVSS 9.8 critical and is listed in CISA's KEV catalog, making it a high-priority target for defenders.

Impact

An attacker with network access to vCenter can execute arbitrary code on the appliance, potentially gaining full control of the virtualization management plane. This could lead to compromise of managed hosts, virtual machines, and credential material.

Attack surface

Reachable over the network via the vCenter Syslog server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is required. Any internet-exposed or internally reachable vCenter instance running the affected service is at risk.

Exploitation

CVE-2026-59310 is in CISA's KEV catalog with a due date of 2026-08-21 and is flagged for known ransomware campaign use. EPSS probability is 0.45878 (98.7th percentile), and third-party advisories describe active exploitation across many countries.

What to do

  • Apply the vendor patch from Broadcom's security advisory for vCenter Server immediately.
  • If patching is not possible, restrict network access to the vCenter Syslog server to trusted management networks only.
  • Follow CISA BOD 26-04 guidance, including forensics triage requirements, and consider discontinuing use if mitigations are unavailable.
  • Monitor for and block known exploitation indicators associated with this CVE from the referenced third-party advisories.
  • Verify vCenter backups and isolate compromised instances before restoring.

Detection

  • Review vCenter Syslog server logs for path traversal patterns such as ../ sequences in incoming requests.
  • Monitor for unexpected process creation or outbound connections from the vCenter appliance.
  • Check for unauthorized changes to vCenter configuration, scheduled tasks, or new administrative accounts.
  • Correlate network traffic to vCenter Syslog ports with threat intelligence feeds for CVE-2026-59310 exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-59310 to the Known Exploited Vulnerabilities catalog on 18 August 2026 as "Broadcom VMware vCenter Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 21 August 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-59310 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed9.8CVE-2020-3952VMware vCenter Server vmdir missing authentication access control flawThe vmdir service shipped with VMware vCenter Server, as part of an embedded or external Platform Services Controller, does not correctly implement a…KEVEPSS 90%analysed

Source: NIST National Vulnerability Database (record CVE-2026-59310), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.