Sploitus Critical Path Traversal Vulnerability in VMware vCenter Server
Article Content
- •CVE-2026-59310 allows remote code execution via path traversal in VMware vCenter Server.
- •Exploitation requires only access to the syslog port; no credentials are needed.
- •Active exploitation has been confirmed, and patches are available for affected versions.
A critical vulnerability, CVE-2026-59310, has been identified in VMware vCenter Server that allows for unauthorized remote code execution through a path traversal exploit. This flaw affects versions prior to 9.0.2.0 / Build 25148086, where attackers can exploit the syslog service by sending specially crafted messages to the syslog port (UDP/TCP 514) without requiring credentials. The vulnerability arises from the use of dynamic path templates that concatenate untrusted fields, enabling attackers to write arbitrary files and execute code with root privileges. The exploit has been publicly documented, with proof-of-concept code available since August 17, 2026. As of August 18, 2026, this vulnerability has been added to the CISA KEV catalog due to active exploitation in the wild. Organizations using affected versions are urged to apply patches immediately to mitigate potential attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-59310 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numerous applications…