PT-2026-65833 · Vmware · Vcenter+1

CVE-2026-59310

·

Published

2026-07-29

·

Updated

2026-09-10

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter versions prior to 9.1.0.0300 VMware vCenter versions prior to 9.0.2.0100 VMware vCenter versions prior to 8.0 U3k VMware vCenter versions prior to 8.0 U2f
Description VMware vCenter contains a directory traversal flaw in the Syslog server caused by improper restriction of directory path names. An unauthenticated malicious actor with network access can exploit this issue to execute arbitrary code on the system. Real-world exploitation has been observed across 361 unique IP addresses in 47 countries, including the US, Germany, Turkey, Iran, and France. Attackers have used this flaw to deploy a reverse SSH framework for persistent remote access and have been linked to a suspected China-nexus APT group. In some instances, a Babuk-derived ransomware variant was deployed as a distraction to mask long-term espionage activities.
Recommendations Update VMware vCenter to version 9.1.0.0300. Update VMware vCenter to version 9.0.2.0100. Update VMware vCenter to version 8.0 U3k. Update VMware vCenter to version 8.0 U2f. Restrict network access to vCenter management interfaces to trusted IP addresses only.

Exploit

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11333
CVE-2026-59310

Affected Products

Vmware Vcenter
Vcenter