Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-59310

vCenter directory-traversal vulnerability

VMware / Cloud Foundation · 9.1.x.x

Severity
CVSS 9.8 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
1.1%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-59310 is an unauthenticated vCenter directory-traversal vulnerability affecting VMware Cloud Foundation and 4 other products. VMware vCenter contains a directory traversal vulnerability in the Syslog...

Is it exploited?

Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.

Who is affected?

VMware / Cloud Foundation 9.1.x.x.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Vendor Product Affected Status
VMware Cloud Foundation 9.1.x.x Affected
VMware Cloud Foundation 9.0.x.x Affected
VMware Cloud Foundation 5.x Affected
VMware vSphere Foundation 9.1.x.x Affected
VMware vSphere Foundation 9.0.x.x Affected
VMware vCenter Before 9.1.0.0300 Affected
VMware vCenter Before 9.0.2.0100 Affected
VMware vCenter Before 8.0 U3k Affected
VMware Telco Cloud Infrastructure 3.0 Affected
VMware Telco Cloud Platform 5.1.x Affected
VMware Telco Cloud Platform 5.0.x Affected
VMware Telco Cloud Platform 4.x Affected
VMware Telco Cloud Platform 3.0 Affected
Published
30 Jul 2026
Exploitation Reported
12 Aug 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

cisa

CVE References

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

TheHackerNews

Recorded 12 Aug 2026

Independent exploitation attestation added to the KEV Intelligence record.

Proof of concept available

GitHub

Recorded 17 Aug 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
TheHackerNews First 2026-08-12 10:47 UTC
BleepingComputer 2026-08-13 16:40 UTC
CISA 2026-08-18 16:52 UTC
CVE 2026-08-18 17:51 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
0
User-Agents
0

Raw values available in Pro and Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

1.1%

Recent mention · TheHackerNews

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe...

Read full advisory

All Mentions

Recent mention · TheHackerNews

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

TheHackerNews · 17 Aug 2026

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

Recent mention · BleepingComputer

Critical VMware vCenter RCE flaw exploited for reverse SSH access

BleepingComputer · 13 Aug 2026

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

Recent mention · TheHackerNews

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

TheHackerNews · 12 Aug 2026

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

Recent mention · Rapid7

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 · 30 Jul 2026

OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

BiuTrap/CVE-2026-59310

github · Created 2026-08-17 10:09:51 UTC · 0 stars · AI assessment 85%

CVE-2026-59310 PoC

HORKimhab/CVE-2026-59310

github · Created 2026-08-17 07:51:46 UTC · 0 stars · AI assessment 90%

CVE-2026-59310

Timeline

From disclosure to observed exploitation

  1. KEV confirmed by CVE

    Exploitation attested by an external source

  2. Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  3. Public PoC available

    Public proof-of-concept code published

  4. KEV confirmed by BleepingComputer

    Exploitation attested by an external source

  5. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  6. CVE published

    Vulnerability disclosed publicly

  7. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-59310

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-59310",
  "confidence": "Confirmed",
  "cvss_score": 9.8,
  "cvss_estimated": false,
  "epss_score": 0.0114,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.