CVE-2026-59310
Vulnerability Summary
Timeline
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 2.56%• Percentile: 85%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- vmware•cloud foundation
9.1.x.x | 9.0.x.x | ≥ 5.0, < 6.0
- vmware•telco cloud infrastructure
3.0
- vmware•telco cloud platform
≥ 5.1.0, < 5.2.0 | ≥ 5.0.0, < 5.1.0 | ≥ 4.0, < 5.0 | 3.0
- vmware•vcenter
≥ 9.1.x.x, < 9.1.0.0300 | ≥ 9.0.x.x, < 9.0.2.0100 | ≥ 8.0, < 8.0 U3k
- vmware•vcenter_server
< 8.0 | 8.0 | 8.0:a | 8.0:b | 8.0:c | 8.0:update1 | 8.0:update1a | 8.0:update1b | 8.0:update1c | 8.0:update1d | 8.0:update1e | 8.0:update2 | 8.0:update2a | 8.0:update2b | 8.0:update2c | 8.0:update2d | 8.0:update2e | 8.0:update3 | 8.0:update3a | 8.0:update3b | 8.0:update3c | 8.0:update3d | 8.0:update3e | 8.0:update3g | 8.0:update3h | 8.0:update3i | 8.0:update3j | ≥ 9.0, < 9.0.2.0100 | ≥ 9.1, < 9.1.0.0300
- vmware•vsphere foundation
9.1.x.x | 9.0.x.x
References (4)
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
- https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310