CVE-2026-59310 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-59310 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-59310 is a directory traversal vulnerability in the VMware vCenter Syslog server component that can be reached by an attacker with network access to vCenter.
Technical Detail
The flaw permits path traversal through the Syslog server, potentially allowing an attacker to access or manipulate files outside the intended directory scope. A malicious actor with network connectivity to a vulnerable vCenter instance may exploit the issue to execute arbitrary code, resulting in remote code execution (RCE). The available information does not specify the required request format, affected versions, authentication requirements, or vendor-provided workaround details.
Exploitation Status
No known public exploit or confirmed in-the-wild exploitation has been reported as of August 06, 2026. CVE-2026-59310 is not listed in CISA's Known Exploited Vulnerabilities catalog.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this issue as a critical patching priority and apply the applicable VMware vCenter security update as soon as it is available. Restrict network access to vCenter management interfaces and Syslog-related services to authorized administrative networks, avoid exposing vCenter directly to untrusted networks, and review firewall rules and segmentation controls. Monitor vCenter and Syslog service logs for anomalous requests, unexpected file-access activity, service errors, or suspicious child processes that may indicate exploitation attempts. Confirm affected versions and any vendor-recommended mitigations with VMware security advisories, as affected-product and workaround information is not provided in the available CVE record.