VMware vCenter RCE exploited in wild (CVE-2026-59310)
CVE-2026-59310
CVE-2026-59310: VMware vCenter Syslog server directory traversal grants unauthenticated RCE (CVSS 9.8). Actively exploited; apply vendor hotfix now.
Actively exploited in the wild - CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Server Syslog service that grants unauthenticated remote code execution (RCE) to network-accessible attackers. VMware has released a hotfix; apply it immediately.
Overview
CVE-2026-59310 is a directory traversal flaw in the Syslog server component of VMware vCenter Server. The vulnerability stems from improper validation of file paths in the Syslog service, allowing an attacker to escape the intended directory structure.
A malicious actor with network access to the Syslog endpoint can exploit this issue to execute arbitrary code on the underlying operating system. Because the Syslog service runs with elevated privileges, successful exploitation can lead to full compromise of the vCenter Server host.
The vulnerability carries a CVSS score of 9.8 (Critical) due to:
- Network-based attack vector
- Low attack complexity
- No privileges required
- No user interaction needed
The CISA Known Exploited Vulnerabilities (KEV) catalog lists CVE-2026-59310 as confirmed actively exploited. The EPSS score of 1.1% indicates a significant probability of exploitation within the next 30 days, reflecting active threat actor interest.
Impact
An attacker exploiting this flaw can:
- Execute arbitrary code with elevated privileges on the vCenter Server
- Gain full administrative control over virtual infrastructure
- Access, modify, or delete sensitive VM data and configurations
- Move laterally within the virtualized environment
- Disrupt operations of all managed ESXi hosts
Given vCenter Server’s central role in managing virtual infrastructure, successful exploitation represents a severe risk to the entire data center environment. The active exploitation status elevates the urgency for immediate remediation.
Remediation
VMware has released hotfixes for affected versions. Apply the vendor-supplied patch immediately. If patching is not immediately feasible:
- Restrict network access to the Syslog service (default port 514) to trusted hosts only
- Place vCenter Server behind a firewall with strict allowlists
- Monitor Syslog traffic for anomalous directory traversal patterns
- Review recent access logs for indicators of compromise
- Isolate vCenter Server from internet-facing networks entirely
Organizations without an immediate patch window should treat this as a high-priority incident and implement compensating controls until the hotfix can be deployed.
For broader context on actively exploited infrastructure vulnerabilities, see CISA Flags SolarWinds, Ivanti, and Workspace One and CISA Adds Actively Exploited VMware Aria Operations.
Security Insight
This vulnerability follows a concerning pattern of VMware infrastructure products becoming prime targets for state-sponsored and financially motivated threat actors alike. The focus on syslog infrastructure, a service many organizations leave exposed and under-monitored, reflects a broader shift toward attacking management-plane services rather than edge devices. The CISA KEV listing within days of disclosure demonstrates how quickly weaponized exploits propagate once infrastructure-level flaws become public.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut...
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or St...
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can...
SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By expl...