CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-18. EPSS: 2.6% chance of exploitation in the next 30 days.
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Affected products
- VMware vCenter Server: before 8.0 (fixed in 8.0); version 8.0 only; from 9.0, before 9.0.2.0100 (fixed in 9.0.2.0100); from 9.1, before 9.1.0.0300 (fixed in 9.1.0.0300)
Published 2026-07-30. Last modified 2026-08-19.