CVE-2026-59310
Last modified
CVE-2026-59310 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.. CISA has confirmed active exploitation in the wild. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Vcenter Server | < 8.0 |
| Vmware | Vcenter Server | 8.0 |
| Vmware | Vcenter Server | >= 9.0, < 9.0.2.0100 |
| Vmware | Vcenter Server | >= 9.1, < 9.1.0.0300 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59310?
How severe is CVE-2026-59310?
How do I fix CVE-2026-59310?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59304Improper caching of the original content type in Spring Clou…3.8
- CVE-2026-59305Partition interceptor may be improperly added while sending …3.8
- CVE-2026-59306Potential for deserialization of untrusted types in Spring C…3.8
- CVE-2026-59307An operator who calls JdbcMessageStore.addAllowedPatterns(..…8
- CVE-2026-59308In Spring AI's Semantic Cache support, the context hash used…4.3
- CVE-2026-59309VMware vCenter contains an authentication bypass vulnerabili…9.8
- CVE-2026-59311A local unprivileged user on the same host can redirect all …6.8
- CVE-2026-59313Spring MVC applications using the functional web framework a…9.8
- CVE-2026-59314Applications that build a Content-Disposition header value f…3.7
- CVE-2026-59315The Spring Cloud Config Monitor is susceptible to Denial of …5.3
- CVE-2026-59316Spring Authorization Server's default consent page renders u…8.2
- CVE-2026-59317DeadLetterPublishingRecovererFactory reads the retry_topic-o…6.5
Are you affected by CVE-2026-59310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
