VMware vCenter bug can let attackers run code

Published August 10, 2026 CVE-2026-59310

Attackers who can reach VMware vCenter can run their own code. CISA lists this flaw as exploited.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Fixed in 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f +1Fix recorded on Aug 26, 2026
Affected versions
9.1.x.x before 9.1.0.0300; 9.0.x.x before 9.0.2.0100; 8.0 releases before a matching fixed build+6 more
Weakness
CWE-22Path Traversal
Exploit likelihood
46% in 30 daysEPSS, higher than 99% of known flaws
Affects
VMware vCenter Server+4 more
Exploited
Yes, in the wildListed by CISA, used in ransomware
Added to CISA list
Aug 18, 2026
Federal fix deadline
Aug 21, 2026

How it works

  • An attacker needs network access to vCenter.
  • Its Syslog service has a flaw that lets file paths escape the intended folder.
  • Exploiting that flaw can let the attacker run code.

What to do

Apply the matching vCenter fix: 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f. Cloud Foundation 5.x uses the documented asynchronous patch. Follow KB449886 for Telco products. If you use Broadcom directs vCenter 7.0 with extended support contracts to contact Support, ask your administrator to compare the deployed vCenter release with the Broadcom response matrix. The advisory lists no workaround.

Technical details

Affected software: VMware vCenter Server, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator