Critical severity9.8CISA KEVNVD Advisory· Published Jul 30, 2026· Updated Aug 19, 2026
CVE-2026-59310
CVE-2026-59310
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
28(expand)+ 27 more
- (no CPE)
- cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*range: <8.0
- cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3g:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3h:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3i:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3j:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ffnvdThird Party Advisory
- medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466dnvdThird Party Advisory
- support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
24- Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaSCyber Security News · Sep 8, 2026
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeThe Hacker News · Sep 5, 2026
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe Hacker News · Aug 19, 2026
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesSecurityWeek · Aug 19, 2026
- CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in AttacksCyber Security News · Aug 19, 2026
- VMware vCenter Attackers Drop JSP Webshell Disguised as Performance UpdateCyber Security News · Aug 18, 2026
- VMware CVE-2026-59310 Added to CISA KEV Under Active ExploitationVypr Intelligence · Aug 18, 2026
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareThe Hacker News · Aug 17, 2026
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- vCenter Flaw Exploited Just Five Days After DisclosureInfosecurity Magazine · Aug 13, 2026
- Critical VMware vCenter Vulnerability in Attackers’ CrosshairsSecurityWeek · Aug 13, 2026
- Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote AccessCyber Security News · Aug 12, 2026
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessThe Hacker News · Aug 12, 2026
- Hackers Actively Scanning to Exploit VMware VCenter VulnerabilitiesCyber Security News · Aug 11, 2026
- 3rd August – Threat Intelligence ReportCheck Point Research · Aug 3, 2026
- Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 StoriesCyber Security News · Aug 2, 2026
- VMware fixes three critical flaws allowing auth bypass, VM escapesBleepingComputer · Jul 30, 2026
- Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Rapid7 Blog · Jul 30, 2026
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeThe Hacker News · Jul 29, 2026
- Critical VM Escape Vulnerability Patched in VMware ESXiSecurityWeek · Jul 29, 2026
- Critical VMware Flaws Allow Attackers to Bypass Authentication and Gain Access to the SystemCyber Security News · Jul 29, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts