CVE-2026-59310

Analyzed
Published: 30 Jul 2026, 12:19
Last modified:12 Sept 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
2.56% LOW
3% probability 0.00%
KEV
Listed
CISA • ENISA
2 listings
Ransomware
Known Use
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 12:19
Published
Vulnerability first disclosed
10 Aug 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
18 Aug 2026, 00:00
Added to CISA KEV
Broadcom VMware vCenter Path Traversal Vulnerability
21 Aug 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
12 Sept 2026, 03:55
Last Modified
Vulnerability information updated

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

CVSS Metrics

  • v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 2.56%• Percentile: 85%

Techniques & Countermeasures

  • CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • vmware•cloud foundation

    9.1.x.x | 9.0.x.x | ≥ 5.0, < 6.0

  • vmware•telco cloud infrastructure

    3.0

  • vmware•telco cloud platform

    ≥ 5.1.0, < 5.2.0 | ≥ 5.0.0, < 5.1.0 | ≥ 4.0, < 5.0 | 3.0

  • vmware•vcenter

    ≥ 9.1.x.x, < 9.1.0.0300 | ≥ 9.0.x.x, < 9.0.2.0100 | ≥ 8.0, < 8.0 U3k

  • vmware•vcenter_server

    < 8.0 | 8.0 | 8.0:a | 8.0:b | 8.0:c | 8.0:update1 | 8.0:update1a | 8.0:update1b | 8.0:update1c | 8.0:update1d | 8.0:update1e | 8.0:update2 | 8.0:update2a | 8.0:update2b | 8.0:update2c | 8.0:update2d | 8.0:update2e | 8.0:update3 | 8.0:update3a | 8.0:update3b | 8.0:update3c | 8.0:update3d | 8.0:update3e | 8.0:update3g | 8.0:update3h | 8.0:update3i | 8.0:update3j | ≥ 9.0, < 9.0.2.0100 | ≥ 9.1, < 9.1.0.0300

  • vmware•vsphere foundation

    9.1.x.x | 9.0.x.x

References (4)