VMware vCenter Exploited via Critical Path Traversal Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in VMware vCenter, identified as CVE-2026-59310, is being actively exploited, allowing attackers to gain full control over virtual infrastructures. The flaw, a directory traversal vulnerability in the Syslog Server, enables command execution as root without a normal login. Incident responders at QUIRSO reported a rapid escalation from disclosure to widespread exploitation within days, mapping 361 affected IP addresses. Additionally, another CVE, CVE-2026-59309, was published on the same date but is possibly unrelated. The first public proof of concept (PoC) for CVE-2026-59310 was released on August 17, 2026, intensifying the urgency for organizations to address this vulnerability. Organizations using VMware vCenter are at significant risk if they do not implement immediate mitigations.
Key Points: • CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter. • Attackers can execute commands as root, compromising entire virtual infrastructures. • 361 IP addresses have been identified as affected, highlighting the scale of the exploitation.