VMware vCenter bug can let attackers run code
Attackers who can reach VMware vCenter can run their own code. CISA lists this flaw as exploited.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Fixed in 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f +1Fix recorded on Aug 26, 2026
- Affected versions
- 9.1.x.x before 9.1.0.0300; 9.0.x.x before 9.0.2.0100; 8.0 releases before a matching fixed build+6 more
- Weakness
- CWE-22Path Traversal
- Exploit likelihood
- 46% in 30 daysEPSS, higher than 99% of known flaws
- Affects
- VMware vCenter Server+4 more
- Exploited
- Yes, in the wildListed by CISA, used in ransomware
- Added to CISA list
- Aug 18, 2026
- Federal fix deadline
- Aug 21, 2026
How it works
- An attacker needs network access to vCenter.
- Its Syslog service has a flaw that lets file paths escape the intended folder.
- Exploiting that flaw can let the attacker run code.
What to do
Apply the matching vCenter fix: 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f. Cloud Foundation 5.x uses the documented asynchronous patch. Follow KB449886 for Telco products. If you use Broadcom directs vCenter 7.0 with extended support contracts to contact Support, ask your administrator to compare the deployed vCenter release with the Broadcom response matrix. The advisory lists no workaround.
Technical details
Affected software: VMware vCenter Server, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- support.broadcom.com · 38017 CCCS Canada Vendor Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog CCCS Canada US Government Resource
- medium.com · active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff Third Party Advisory
- medium.com · global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d Third Party Advisory
- cyber.gc.ca · vmware-security-advisory-av26-763 CCCS Canada
- support.broadcom.com · security-advisory CCCS Canada