Directory Traversal Vulnerability in VMware vCenter by VMware
CVE-2026-59310

9.8CRITICAL

Key Information:

Vendor

Vmware

Vendor
CVE Published:
30 July 2026

Badges

🔥 Trending now📈 Trended📈 Score: 7,830💰 Ransomware👾 Exploit Exists🟡 Public PoC🦅 CISA Reported📰 News Worthy

What is CVE-2026-59310?

CVE-2026-59310 is a severe directory traversal vulnerability identified in VMware vCenter, a centralized platform for managing VMware hypervisors and virtual machines. This vulnerability exists in the Syslog server component of vCenter, allowing a malicious actor with network access to potentially execute arbitrary code on the affected systems. Such code execution could lead to unauthorized access to sensitive data, manipulation of system configurations, or even complete control over the virtualized environment. Given that vCenter manages multiple virtual machines and critical organizational workloads, exploitation of this vulnerability can severely compromise an organization’s IT infrastructure, leading to operational disruption and significant security risks.

Potential impact of CVE-2026-59310

  1. Arbitrary Code Execution: The most immediate concern is the ability for attackers to execute arbitrary code on the vCenter server. This could allow them to deploy malware, establish backdoors, or escalate their privileges, posing a critical threat to security and confidentiality.

  2. System Compromise: Successful exploitation can lead to full system compromise, enabling attackers to manipulate the virtualized assets managed by vCenter. This could include altering virtual machine settings, disrupting services, and even gaining access to sensitive data hosted on those machines.

  3. Operational Disruption: The exploitation of this vulnerability could lead to significant operational disruptions. Organizations rely on vCenter for managing their virtual infrastructure, and a successful attack could result in downtime, data loss, and a degradation of service quality, ultimately affecting business continuity and performance.

CISA has reported CVE-2026-59310

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-59310 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Cloud Foundation 9.1.x.x

Cloud Foundation 9.0.x.x

Cloud Foundation 5.x

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update - IT Security News

2026-08-18 12:08 A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a critical path...

1 day ago

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A suspected China-nexus actor exploits CVE-2026-59310, compromising an estimated 361 IPs in 47 countries and gaining root execution on vCenter.

2 days ago

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.

6 days ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🦅

    CISA Reported

  • 🟡

    Public PoC available

  • 💰

    Used in Ransomware

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.