CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 18, 2026
- US federal agencies must remediate it by Aug 21, 2026 (BOD 22-01)
- First attack observed 11 days after disclosure
- Used in ransomware campaigns
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 8, 2026 Aug 21, 2026 Aug 18, 2026 Aug 14, 2026 Aug 12, 2026 Aug 10, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| vmware | vcenter server | < 8.0 |
| vmware | telco cloud infrastructure | 3.0 |
| vmware | telco cloud platform | <= 5.2 |
| vmware | cloud foundation | - |
| vmware | vsphere foundation | - |
Related articles
VulnerabilitiesVMware patches critical flaws: VM escape and risk of total control of the virtual infrastructure
Broadcom patched critical VMware flaws in ESXi and vCenter. Updates fix severe VM escape and RCE flaws risking total virtual infrastructure control.
VulnerabilitiesVMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access
CVE-2026-59310 exploitation in VMware vCenter allows persistent access via cron jobs and reverse_ssh. Apply patches to mitigate.
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesGitea Under Attack: Critical RCE Exploited for Cryptojacking, CISA Mandates Patch by August 28
Critical RCE in Gitea (CVE-2026-60004) is being exploited for cryptojacking. CISA requires federal agencies to patch by August 28, 2026.
VulnerabilitiesVMware Workstation and Fusion: Two Flaws Allow Escape from the Virtual Machine
Broadcom fixed two critical VMware Workstation and Fusion flaws allowing VM escape to host. Upgrade to 26H1u1 to patch CVE-2026-59346, CVE-2026-59347.
This product uses the NVD API but is not endorsed or certified by the NVD.