CISA added CVE-2026-59310, a CVSS 9.8 directory traversal flaw in the VMware vCenter Syslog server that allows unauthenticated remote code execution, to the Known Exploited Vulnerabilities catalog on 2026-08-18 with a three-day remediation deadline.
What Is It
VMware vCenter contains a directory traversal vulnerability (CWE-22) in the Syslog server. Per the vendor advisory, a malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.
Why It Matters
CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision points classify exploitation as active, automatable as yes, and technical impact as total: meaning attackers can reliably script this against exposed instances for complete system takeover. Known ransomware campaign use is currently listed as Unknown.
The due date of 2026-08-21, just three days after the 2026-08-18 KEV addition, signals unusually high urgency relative to standard KEV timelines.
What's Vulnerable
Affected VMware products and versions:
- vCenter: 9.1.x.x before 9.1.0.0300; 9.0.x.x before 9.0.2.0100; 8.0 before 8.0 U3k
- Cloud Foundation: 9.1.x.x, 9.0.x.x, 5.x
- vSphere Foundation: 9.1.x.x, 9.0.x.x
- Telco Cloud Infrastructure: 3.0
- Telco Cloud Platform: 5.1.x, 5.0.x, 4.x, 3.0
Patch Status
Fixed vCenter builds are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k. Consult the Broadcom advisory for guidance covering Cloud Foundation, vSphere Foundation, and Telco Cloud products.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 ("Prioritizing Security Updates Based on Risk") and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines.
Sources
- Broadcom Security Advisory 38017
- NVD, CVE-2026-59310
- CISA Known Exploited Vulnerabilities Catalog
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements
- Active Exploitation of CVE-2026-59310: 361 Victim IPs Across 47 Countries
- Global Exploitation of CVE-2026-59310 by Suspected Chinese-Nexus APT