CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-18. EPSS: 2.6% chance of exploitation in the next 30 days.

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Affected products

  • VMware vCenter Server: before 8.0 (fixed in 8.0); version 8.0 only; from 9.0, before 9.0.2.0100 (fixed in 9.0.2.0100); from 9.1, before 9.1.0.0300 (fixed in 9.1.0.0300)

Published 2026-07-30. Last modified 2026-08-19.