ThreatCluster

Active Exploitation of VMware vCenter Path Traversal Vulnerability CVE-2026-59310

First seen 18 Aug 2026, 12:35 UTC GbhackersCybersecuritynewsnvd.nist.gov 77

Article Content

Browse articles
ThreatCluster

A critical vulnerability in VMware vCenter, tracked as CVE-2026-59310, is being actively exploited, allowing attackers to execute arbitrary code via a path traversal flaw in the Syslog Server. This vulnerability, disclosed on July 30, 2026, was added to CISA's Known Exploited Vulnerabilities Catalog on August 18, 2026. Attackers are leveraging this flaw to gain full control over virtual infrastructures, with reports indicating at least 361 affected IP addresses. The exploitation escalated rapidly, with a public proof of concept released on August 17, 2026. A separate vulnerability, CVE-2026-59309, has also been identified but is considered possibly unrelated. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings regarding the ongoing exploitation. Organizations using affected VMware vCenter deployments are urged to take immediate action to mitigate risks.

Key Points: • CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter. • Active exploitation allows attackers to execute arbitrary code on affected systems. • CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog.

Ask AI about this cluster

Timeline

2026-07-30
CVE-2026-59310 published
VMware disclosed a critical path traversal vulnerability in vCenter affecting Syslog Server.
nvd.nist.gov
2026-07-30
CVE-2026-59309 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-17
First public PoC released
A proof of concept for CVE-2026-59310 was made publicly available, facilitating exploitation.
Gbhackers
2026-08-18
CISA adds CVE-2026-59310 to KEV Catalog
CISA confirmed active exploitation of the vulnerability and included it in the Known Exploited Vulnerabilities Catalog.
Gbhackers
Recent
361 IPs affected by exploitation
QUIRSO identified at least 361 IP addresses impacted by the exploitation of CVE-2026-59310.
Cybersecuritynews