ThreatCluster

VMware vCenter Exploited via Critical Path Traversal Vulnerability

First seen 18 Aug 2026, 12:35 UTC GbhackersCybersecuritynews 76% similarity 75

Article Content

Browse articles
ThreatCluster

A critical vulnerability in VMware vCenter, identified as CVE-2026-59310, is being actively exploited, allowing attackers to gain full control over virtual infrastructures. The flaw, a directory traversal vulnerability in the Syslog Server, enables command execution as root without a normal login. Incident responders at QUIRSO reported a rapid escalation from disclosure to widespread exploitation within days, mapping 361 affected IP addresses. Additionally, another CVE, CVE-2026-59309, was published on the same date but is possibly unrelated. The first public proof of concept (PoC) for CVE-2026-59310 was released on August 17, 2026, intensifying the urgency for organizations to address this vulnerability. Organizations using VMware vCenter are at significant risk if they do not implement immediate mitigations.

Key Points: • CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter. • Attackers can execute commands as root, compromising entire virtual infrastructures. • 361 IP addresses have been identified as affected, highlighting the scale of the exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-07-30
CVE-2026-59310 published
VMware disclosed a critical path traversal vulnerability affecting vCenter systems.
Gbhackers
2026-07-30
CVE-2026-59309 published
Another vulnerability related to VMware vCenter was published, potentially unrelated to CVE-2026-59310.
Gbhackers
2026-08-17
First public PoC for CVE-2026-59310 released
A proof of concept for exploiting the critical vulnerability was made public, increasing urgency for remediation.
Gbhackers
Recent
Widespread exploitation observed
Attackers rapidly moved from disclosure to exploitation, impacting numerous organizations globally.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story