Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-59310KEVEXPLOITEDPATCHED
vmware · vcenter_server

vCenter directory-traversal vulnerability

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Affected Products

VendorProductVersions
vmwarevcenter_server9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 3.0, 5.1.x, 5.0.x, 4.x, 3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
vmwarevsphere foundationmitre_affected90%
vmwarevcentermitre_affected90%
vmwaretelco cloud infrastructuremitre_affected90%
vmwaretelco cloudmitre_affected90%
vmwaretelco_cloud_infrastructurecve_cpe95%

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Related News (18 articles)

Tier D
The Hacker News10d ago
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
→ No new info (linked only)
Tier D
BleepingComputer12d ago
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
→ No new info (linked only)
Tier D
Heise Security39d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier D
The Hacker News41d ago
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
→ No new info (linked only)
Tier D
The Hacker News41d ago
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
→ No new info (linked only)
Tier D
BleepingComputer45d ago
Critical VMware vCenter RCE flaw exploited for reverse SSH access
→ No new info (linked only)
Tier D
Infosecurity Magazine45d ago
vCenter Flaw Exploited Just Five Days After Disclosure
→ No new info (linked only)
Tier D
SecurityWeek45d ago
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
→ No new info (linked only)
Tier D
Heise Security45d ago
Attacken auf VMware vCenter durch Path-Traversal-Lücke
→ No new info (linked only)
Tier D
The Hacker News46d ago
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
→ No new info (linked only)
Tier D
CSO Online58d ago
Broadcom patches vulnerabilities all over VMware
→ No new info (linked only)
Tier D
BleepingComputer59d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
→ No new info (linked only)
Tier B
CCCS Canada59d ago
VMware security advisory (AV26-763)
→ No new info (linked only)
Tier C
VulDB59d ago
CVE-2026-59310 | VMware vCenter Syslog server path traversal
→ No new info (linked only)
Tier D
Heise Security59d ago
VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken
→ No new info (linked only)
Tier C
Rapid7 Blog59d ago
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
→ No new info (linked only)
Tier B
CERT-FR60d ago
Multiples vulnérabilités dans les produits VMware (30 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories60d ago
[NEU] [hoch] VMware Produkte: Mehrere Schwachstellen
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
9.1.0.03009.0.2.01008.0 U3k
CWECWE-22
PublishedJul 30, 2026
Last enriched59d ago
Trending Score39
Source articles18
Independent11
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59309EXPKEV
vCenter authentication-bypass vulnerability
Trending: 66
MEDIUMCVE-2026-59296
Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability
Trending: 5
MEDIUMCVE-2026-59355
Spring Authorization Server: Open Redirect via request_uri parameter
Trending: 1
MEDIUMCVE-2026-59323
Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
Trending: 1
HIGHCVE-2026-47866
VMware Avi Load Balancer Authorization Bypass Vulnerability

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Added to CISA KEV
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Actively Exploited
Sep 12, 2026
Patch Available
Sep 12, 2026