Posts

CVE-2026-59310 Critical Exploit VMware vCenter Server

Image
  CVE-2026-59310 is a critical VMware vCenter Server directory traversal vulnerability affecting the vCenter Syslog Server component. It has a CVSS score of 9.8 (Critical) . An attacker with network access to a vulnerable vCenter instance can exploit the flaw to achieve arbitrary code execution on the vCenter server. Key Details CVE: CVE-2026-59310 Severity: Critical (CVSS 9.8) Type: Directory Traversal (Path Traversal) Affected Component: VMware vCenter Syslog Server Impact: Remote Code Execution (RCE) Attack Prerequisites: Network access to the vulnerable vCenter service Authentication Required: No authentication required according to Broadcom's advisory and industry reporting. Affected Products Broadcom lists the following as affected: VMware vCenter VMware Cloud Foundation VMware vSphere Foundation VMware Telco Cloud Platform VMware Telco Cloud Infrastructure Fixed Versions Broadcom released patches in: vCenter 9.1.x → fixed in 9.1.0.0300 vCenter 9.0.x → fixed in ...