CVE-2026-59310 Details
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
A directory traversal vulnerability has been identified in the Syslog server of VMware vCenter. This vulnerability allows a malicious actor with network access to vCenter to execute arbitrary code. The issue is present in multiple versions of vCenter, as well as in VMware ESX, Workstation, and Fusion.
Users can upgrade to vCenter versions 9.1.0.0300, 9.0.2.0100, or 8.0 U3k. For VMware Cloud Foundation 5.x, an asynchronous patch to 8.0 U3k is available. VMware Workstation and Fusion users can upgrade to version 26H1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff | CISA-ADP | Third Party Advisory |
| https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d | CISA-ADP | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310 | CISA-ADP | US Government Resource |
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Broadcom VMware vCenter Path Traversal Vulnerability | Aug 18, 2026 | Aug 21, 2026 | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vmware vcenter server | < 8.0 8.0 - 8.0 a 8.0 b 8.0 c 8.0 update1 8.0 update1a 8.0 update1b 8.0 update1c 8.0 update1d 8.0 update1e 8.0 update2 8.0 update2a 8.0 update2b 8.0 update2c 8.0 update2d 8.0 update2e 8.0 update3 8.0 update3a 8.0 update3b 8.0 update3c 8.0 update3d 8.0 update3e 8.0 update3g 8.0 update3h 8.0 update3i 8.0 update3j >= 9.0, < 9.0.2.0100 >= 9.1, < 9.1.0.0300 |
CPE
Remediation
| |
| vmware telco cloud infrastructure | 3.0 |
CPE
Remediation
| |
| vmware telco cloud platform | >= 3.0, <= 5.2 |
CPE
Remediation
| |
| vmware cloud foundation | All versions |
CPE
Remediation
| |
| vmware vsphere foundation | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Aug 18, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 18, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2026 | CVE Modified | CISA-ADP |
| Aug 13, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |