PT-2026-65833 · Vmware · Vcenter+1
CVE-2026-59310
·
Published
2026-07-29
·
Updated
2026-09-24
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware vCenter versions prior to 9.1.0.0300
VMware vCenter versions prior to 9.0.2.0100
VMware vCenter versions prior to 8.0 U3k
VMware vCenter versions prior to 8.0 U2f
Description
VMware vCenter contains a directory traversal flaw in the Syslog server caused by improper restriction of directory path names. An unauthenticated attacker with network access can exploit this issue to execute arbitrary code. This flaw has been actively exploited by advanced persistent threat actors and ransomware gangs, with over 361 compromised IP addresses identified across 47 countries. Attackers have used the vulnerability to establish persistence via
reverse ssh tools, create privileged vSphere identities, and deploy ransomware. Shadowserver has tracked more than 450 VMware vCenter servers exposed to the public internet.Recommendations
Update VMware vCenter to version 9.1.0.0300.
Update VMware vCenter to version 9.0.2.0100.
Update VMware vCenter to version 8.0 U3k.
Update VMware vCenter to version 8.0 U2f.
Exploit
Fix
RCE
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter
Vcenter