Junglewise Threat Intelligence

CVE-2026-59310: VMware vCenter directory traversal in Syslog server

CVE-2026-59310 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-07-30

Executive brief

Broadcom VMware vCenter is virtualization management software used by enterprises to manage their data center infrastructure. A path traversal vulnerability allows attackers with network access to bypass security controls and execute arbitrary code on the vCenter server, potentially compromising all virtual machines and data managed by the platform.

Technical details

A path traversal vulnerability exists in Broadcom VMware vCenter that enables unauthenticated or low-privileged attackers with network access to traverse the filesystem and access restricted files or resources. The vulnerability allows an attacker to break out of intended directory restrictions by using path traversal sequences (such as "../"), potentially leading to arbitrary code execution on the vCenter server. The attack requires network reachability to vCenter but does not appear to require prior authentication. The vulnerability has been confirmed as actively exploited in the wild, indicating that real-world threat actors have weaponized this flaw. A patch or upgrade is recommended to remediate this critical issue.

Affected products

  • Broadcom VMware vCenter

Timeline

  • 2026-08-18: disclosed
  • exploited: Confirmed exploitation in the wild

Related threats