Skip to content
Critical Path Traversal Vulnerability in VMware vCenter Server

Critical Path Traversal Vulnerability in VMware vCenter Server

First seen 29 Sep 2026, 04:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •CVE-2026-59310 allows remote code execution via path traversal in VMware vCenter Server.
  • •Exploitation requires only access to the syslog port; no credentials are needed.
  • •Active exploitation has been confirmed, and patches are available for affected versions.

A critical vulnerability, CVE-2026-59310, has been identified in VMware vCenter Server that allows for unauthorized remote code execution through a path traversal exploit. This flaw affects versions prior to 9.0.2.0 / Build 25148086, where attackers can exploit the syslog service by sending specially crafted messages to the syslog port (UDP/TCP 514) without requiring credentials. The vulnerability arises from the use of dynamic path templates that concatenate untrusted fields, enabling attackers to write arbitrary files and execute code with root privileges. The exploit has been publicly documented, with proof-of-concept code available since August 17, 2026. As of August 18, 2026, this vulnerability has been added to the CISA KEV catalog due to active exploitation in the wild. Organizations using affected versions are urged to apply patches immediately to mitigate potential attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-30
CVE-2026-59310 published
VMware disclosed a critical path traversal vulnerability in vCenter Server affecting multiple versions.
Sploitus
2026-08-17
First public PoC released
Proof-of-concept code for exploiting CVE-2026-59310 was made publicly available.
Sploitus
2026-08-18
CISA adds CVE to KEV catalog
CISA included CVE-2026-59310 in its Known Exploited Vulnerabilities catalog due to confirmed exploitation.
Sploitus
2026-09-29
Exploit details published
Further details on the exploit were published, emphasizing the vulnerability's severity and impact.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-59310 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed