PT-2026-65833 · Vmware · Vcenter+1

CVE-2026-59310

·

Published

2026-07-29

·

Updated

2026-09-24

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter versions prior to 9.1.0.0300 VMware vCenter versions prior to 9.0.2.0100 VMware vCenter versions prior to 8.0 U3k VMware vCenter versions prior to 8.0 U2f
Description VMware vCenter contains a directory traversal flaw in the Syslog server caused by improper restriction of directory path names. An unauthenticated attacker with network access can exploit this issue to execute arbitrary code. This flaw has been actively exploited by advanced persistent threat actors and ransomware gangs, with over 361 compromised IP addresses identified across 47 countries. Attackers have used the vulnerability to establish persistence via reverse ssh tools, create privileged vSphere identities, and deploy ransomware. Shadowserver has tracked more than 450 VMware vCenter servers exposed to the public internet.
Recommendations Update VMware vCenter to version 9.1.0.0300. Update VMware vCenter to version 9.0.2.0100. Update VMware vCenter to version 8.0 U3k. Update VMware vCenter to version 8.0 U2f.

Exploit

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11333
CVE-2026-59310

Affected Products

Vmware Vcenter
Vcenter