PT-2026-65833 · Vmware · Vcenter+1
CVE-2026-59310
·
Published
2026-07-29
·
Updated
2026-09-10
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware vCenter versions prior to 9.1.0.0300
VMware vCenter versions prior to 9.0.2.0100
VMware vCenter versions prior to 8.0 U3k
VMware vCenter versions prior to 8.0 U2f
Description
VMware vCenter contains a directory traversal flaw in the Syslog server caused by improper restriction of directory path names. An unauthenticated malicious actor with network access can exploit this issue to execute arbitrary code on the system. Real-world exploitation has been observed across 361 unique IP addresses in 47 countries, including the US, Germany, Turkey, Iran, and France. Attackers have used this flaw to deploy a reverse SSH framework for persistent remote access and have been linked to a suspected China-nexus APT group. In some instances, a Babuk-derived ransomware variant was deployed as a distraction to mask long-term espionage activities.
Recommendations
Update VMware vCenter to version 9.1.0.0300.
Update VMware vCenter to version 9.0.2.0100.
Update VMware vCenter to version 8.0 U3k.
Update VMware vCenter to version 8.0 U2f.
Restrict network access to vCenter management interfaces to trusted IP addresses only.
Exploit
Fix
RCE
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter
Vcenter