CVE-2026-59310
CRITICALCVSS 9.8/10
Last modified
CVE-2026-59310 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code..
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x; 9.0.x.x; 5.x |
| VMware | vSphere Foundation | 9.1.x.x; 9.0.x.x |
| VMware | vCenter | >= 9.1.x.x, < 9.1.0.0300; >= 9.0.x.x, < 9.0.2.0100; >= 8.0, < 8.0 U3k |
| VMware | Telco Cloud Infrastructure | 3.0 |
| VMware | Telco Cloud Platform | 5.1.x; 5.0.x; 4.x; 3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-59310?
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
How severe is CVE-2026-59310?
CVE-2026-59310 has a CVSS score of 9.8/10 (CRITICAL severity).
How do I fix CVE-2026-59310?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59260OpenWrt luci-app-samba4 read ACL grants file.exec permission…8.8
- CVE-2026-59261OpenClaw before 2026.5.28 contains a credential exposure vul…6.5
- CVE-2026-59262AFFiNE's histories GraphQL field fails to validate Doc.Read …7.1
- CVE-2026-59269A user authenticating to Kubernetes clusters via the Pinnipe…3.8
- CVE-2026-5928Calling the ungetwc function on a FILE stream with wide char…7.5
- CVE-2026-59309VMware vCenter contains an authentication bypass vulnerabili…9.8
- CVE-2026-59326The Spring Boot language server logs the raw value of the ht…3.3
- CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools rem…4.4
- CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard …4.2
- CVE-2026-5935IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9…9.8
- CVE-2026-5936An attacker can control a server-side HTTP request by supply…9.8
- CVE-2026-5937Insufficient parameter verification leads to the occurrence …5.5
Are you affected by CVE-2026-59310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
