What it is
CVE-2026-59310 is an unauthenticated vCenter directory-traversal vulnerability affecting VMware Cloud Foundation and 4 other products. VMware vCenter contains a directory traversal vulnerability in the Syslog...
Vulnerability report
vCenter directory-traversal vulnerability
VMware / Cloud Foundation · 9.1.x.x
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-59310 is an unauthenticated vCenter directory-traversal vulnerability affecting VMware Cloud Foundation and 4 other products. VMware vCenter contains a directory traversal vulnerability in the Syslog...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
VMware / Cloud Foundation 9.1.x.x.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
TheHackerNews
Independent exploitation attestation added to the KEV Intelligence record.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| TheHackerNews First | 2026-08-12 10:47 UTC |
| BleepingComputer | 2026-08-13 16:40 UTC |
| CISA | 2026-08-18 16:52 UTC |
| CVE | 2026-08-18 17:51 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.1%
Recent mention · TheHackerNews
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe...
Read full advisoryRecent mention · TheHackerNews
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareTheHackerNews · 17 Aug 2026
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code
Recent mention · BleepingComputer
Critical VMware vCenter RCE flaw exploited for reverse SSH accessBleepingComputer · 13 Aug 2026
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
Recent mention · TheHackerNews
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote AccessTheHackerNews · 12 Aug 2026
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were
Recent mention · Rapid7
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Rapid7 · 30 Jul 2026
OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-08-17 10:09:51 UTC · 0 stars · AI assessment 85%
CVE-2026-59310 PoC
github · Created 2026-08-17 07:51:46 UTC · 0 stars · AI assessment 90%
CVE-2026-59310
Timeline
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Public proof-of-concept code published
Exploitation attested by an external source
High-confidence, third-party attested exploitation
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-59310
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-59310",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.0114,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.