CVE-2026-59310

Awaiting Analysis
Published: 30 Jul 2026, 12:19
Last modified:14 Aug 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
1.14% LOW
1% probability 0.00%
KEV
Listed
ENISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 12:19
Published
Vulnerability first disclosed
10 Aug 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
14 Aug 2026, 03:55
Last Modified
Vulnerability information updated

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 1.14% Percentile: 64%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • vmwarecloud foundation

    9.1.x.x | 9.0.x.x | ≥ 5.0, < 6.0

  • vmwaretelco cloud infrastructure

    3.0

  • vmwaretelco cloud platform

    ≥ 5.1.0, < 5.2.0 | ≥ 5.0.0, < 5.1.0 | ≥ 4.0, < 5.0 | 3.0

  • vmwarevcenter

    ≥ 9.1.x.x, < 9.1.0.0300 | ≥ 9.0.x.x, < 9.0.2.0100 | ≥ 8.0, < 8.0 U3k

  • vmwarevsphere foundation

    9.1.x.x | 9.0.x.x

References (1)