Active Exploitation of VMware vCenter Path Traversal Vulnerability CVE-2026-59310
Article Content
- •CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter.
- •Active exploitation allows attackers to execute arbitrary code on affected systems.
- •CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog.
A critical vulnerability in VMware vCenter, tracked as CVE-2026-59310, is being actively exploited, allowing attackers to execute arbitrary code via a path traversal flaw in the Syslog Server. This vulnerability, disclosed on July 30, 2026, was added to CISA's Known Exploited Vulnerabilities Catalog on August 18, 2026. Attackers are leveraging this flaw to gain full control over virtual infrastructures, with reports indicating at least 361 affected IP addresses. The exploitation escalated rapidly, with a public proof of concept released on August 17, 2026. A separate vulnerability, CVE-2026-59309, has also been identified but is considered possibly unrelated. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings regarding the ongoing exploitation. Organizations using affected VMware vCenter deployments are urged to take immediate action to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-59309 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…