CVE-2026-59310
published 2026-07-30CVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-21
Exploited in the wild
EPSS
45.88%
98.8th percentile
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | telco_cloud_infrastructure | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | telco_cloud_platform | — | — |
| vmware | vcenter | >= 8.0 < 8.0 U3k | 8.0 U3k |
| vmware | vcenter | >= 9.0.x.x < 9.0.2.0100 | 9.0.2.0100 |
| vmware | vcenter | >= 9.1.x.x < 9.1.0.0300 | 9.1.0.0300 |
| vmware | vcenter_server | < 8.0 | 8.0 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware vCenter Syslog server path traversal
vuldb·2026-08-16·CVSS 9.8
CVE-2026-59310 [CRITICAL] VMware vCenter Syslog server path traversal
A vulnerability, which was classified as very critical, has been found in VMware vCenter. This vulnerability affects unknown code of the component Syslog server. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-59310. Remote exploitation of the attack is possible. No exploit is available.
GHSA
VMware vCenter contains a directory traversal vulnerability in the Syslog server.
ghsa_unreviewed·2026-07-30
CVE-2026-59310 [CRITICAL] CWE-22 VMware vCenter contains a directory traversal vulnerability in the Syslog server.
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
VulnCheck
VMware telco_cloud_infrastructure Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2026·CVSS 9.8
CVE-2026-59310 [CRITICAL] VMware telco_cloud_infrastructure Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
VMware telco_cloud_infrastructure Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Affected: VMware telco_cloud_infrastructure
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff; https://kevintel.com/CVE-2026-59310
VulnCheck
VMware cloud_foundation Incorrect Implementation of Authentication Algorithm
vulncheck·2026·CVSS 9.8
CVE-2026-59309 [CRITICAL] VMware cloud_foundation Incorrect Implementation of Authentication Algorithm
VMware cloud_foundation Incorrect Implementation of Authentication Algorithm
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
Affected: VMware cloud_foundation
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
CISA
Broadcom VMware vCenter Path Traversal Vulnerability
cisa·2026-08-18·CVSS 9.8
CVE-2026-59310 [CRITICAL] CWE-22 Broadcom VMware vCenter Path Traversal Vulnerability
Vulnerability: Broadcom VMware vCenter Path Traversal Vulnerability
Affected: Broadcom VMware vCenter
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://support.broadcom.co
No detection rules found.
No public exploits indexed.
Hackernews
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
blogs_hackernews·2026-08-19·CVSS 9.8
CVE-2026-65400 [CRITICAL] Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild.
The shortcomings added to the KEV catalog are listed below -
CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CVE-2026-55040 (CVSS score: 9.1) - A weak authentication vulnerab
Hackernews
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
blogs_hackernews·2026-08-17·CVSS 9.8
CVE-2026-59310 [CRITICAL] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.
This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely.
So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out.
## ⚡ Threat of the Week
Suspected China APT Behind Exploitation of New V
Hackernews
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
blogs_hackernews·2026-08-17·CVSS 9.8
CVE-2026-59310 [CRITICAL] Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).
The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. A fix for the flaw was released by Broadcom on July 29, 2026.
German incident response company QUIRSO assessed with moderate confidence that
Hackernews
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
blogs_hackernews·2026-08-12·CVSS 9.8
CVE-2026-59310 [CRITICAL] Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were released by Broadcom late last month.
The German cybersecurity company said it discovered the activity following an incident response engagement. The attack
Checkpoint
3rd August – Threat Intelligence Report
blogs_checkpoint·2026-08-03
CVE-2026-59726 3rd August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federa
Rapid7
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
blogs_rapid7·2026-07-30·CVSS 9.8
CVE-2026-59309 [CRITICAL] Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
## Overview
On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.
CVE
CVSSv3.1
Description Summary
CVE-2026-59309
9.8 (Critical)
An authentication bypass vulnerability in the VMware Directory Service of vCenter that could allow a remote attacker to bypass authentication and gain unauthorized access to the vCenter management plane.
CVE-2026-59310
9.8 (Critical)
A directory traversal vulnerability in the
Hackernews
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
blogs_hackernews·2026-07-29
CVE-2026-59309 Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.
"A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said.
The second critical flaw is a directory-traversal v
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ffhttps://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466dhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
2026-07-30
Published
2026-08-18
Added to CISA KEV
Exploited in the wild