CVE-2026-59310
Awaiting Analysis
Published: 30 Jul 2026, 12:19
Last modified:14 Aug 2026, 03:55
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
1.14% LOW
1% probability 0.00%
KEV
Listed
ENISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
30 Jul 2026, 12:19
Published
Vulnerability first disclosed
10 Aug 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
14 Aug 2026, 03:55
Last Modified
Vulnerability information updated
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 1.14%• Percentile: 64%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- vmware•cloud foundation
9.1.x.x | 9.0.x.x | ≥ 5.0, < 6.0
- vmware•telco cloud infrastructure
3.0
- vmware•telco cloud platform
≥ 5.1.0, < 5.2.0 | ≥ 5.0.0, < 5.1.0 | ≥ 4.0, < 5.0 | 3.0
- vmware•vcenter
≥ 9.1.x.x, < 9.1.0.0300 | ≥ 9.0.x.x, < 9.0.2.0100 | ≥ 8.0, < 8.0 U3k
- vmware•vsphere foundation
9.1.x.x | 9.0.x.x