Cybersecurity Blog | RedLegg

Security Bulletin: Directory Traversal Leading to Remote Code Execution in VMware vCenter Syslog Server

Written by RedLegg's Cyber Threat Intelligence Team | 8/14/26, 1:15 PM

About:

CVE-2026-59310 is a critical directory traversal vulnerability affecting the Syslog server component of VMware vCenter Server.

The vulnerability is caused by improper restriction of pathname resolution, allowing a remote attacker with network access to traverse outside the intended directory scope and access unintended resources. No authentication or user interaction is required to exploit the flaw.

Successful exploitation may allow arbitrary code execution on the vCenter server, potentially leading to full compromise of the virtualization management environment. Broadcom has confirmed active exploitation of CVE-2026-59310 in the wild.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

VULNERABILITIES

Directory Traversal Leading to Remote Code Execution in VMware vCenter Syslog Server

Identifier: CVE-2026-59310
PoC or Exploitation:

 Confirmed actively exploited in the wild.  


CVSS Score: 9.8 (Critical, CVSS v3.1)   

Update / Patch:

 
Broadcom has released fixed versions addressing this vulnerability.
 
Affected versions include:
 
VMware vCenter Server, all currently supported branches prior to the fixed versions below
VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure, where these bundle or depend on an affected vCenter version
 
Fixed versions include:

  • VMware vCenter 9.1: 9.1.0.0300
  • VMware vCenter 9.0: 9.0.2.0100
  • VMware vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the deployed branch

Broadcom advisory and patch guidance:
 
Broadcom Security Advisory VMSA-2026-0006.1
 
 

Description:

CVE-2026-59310 is a directory traversal vulnerability in the Syslog server component of VMware vCenter Server, the centralized management platform for VMware vSphere environments.
 
The vulnerability arises from improper restriction of pathname resolution, allowing a remote attacker with network access to the vulnerable vCenter service to traverse outside the intended directory scope and reach unintended resources. Exploitation does not require authentication or user interaction. Successful exploitation can result in arbitrary code execution on the vCenter server.
 
 
 

Mitigation Recommendation:

Apply the applicable fixed version for your vCenter deployment immediately.
 
Prioritize identifying all internet-accessible or otherwise network-reachable vCenter instances.
 
Review vCenter systems for indicators of compromise consistent with reverse SSH persistence tooling, including unexpected outbound connections and unauthorized cron job or scheduled task entries.