Critical 9.8 Actively Exploited

VMware vCenter RCE exploited in wild (CVE-2026-59310)

CVE-2026-59310

By Yazoul AI · automated

CVE-2026-59310: VMware vCenter Syslog server directory traversal grants unauthenticated RCE (CVSS 9.8). Actively exploited; apply vendor hotfix now.

Affected: Vmware Vcenter Server Vmware Telco Cloud Infrastructure Vmware Telco Cloud Platform Vmware Cloud Foundation Vmware Vsphere Foundation

Actively exploited in the wild - CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Server Syslog service that grants unauthenticated remote code execution (RCE) to network-accessible attackers. VMware has released a hotfix; apply it immediately.

Overview

CVE-2026-59310 is a directory traversal flaw in the Syslog server component of VMware vCenter Server. The vulnerability stems from improper validation of file paths in the Syslog service, allowing an attacker to escape the intended directory structure.

A malicious actor with network access to the Syslog endpoint can exploit this issue to execute arbitrary code on the underlying operating system. Because the Syslog service runs with elevated privileges, successful exploitation can lead to full compromise of the vCenter Server host.

The vulnerability carries a CVSS score of 9.8 (Critical) due to:

  • Network-based attack vector
  • Low attack complexity
  • No privileges required
  • No user interaction needed

The CISA Known Exploited Vulnerabilities (KEV) catalog lists CVE-2026-59310 as confirmed actively exploited. The EPSS score of 1.1% indicates a significant probability of exploitation within the next 30 days, reflecting active threat actor interest.

Impact

An attacker exploiting this flaw can:

  • Execute arbitrary code with elevated privileges on the vCenter Server
  • Gain full administrative control over virtual infrastructure
  • Access, modify, or delete sensitive VM data and configurations
  • Move laterally within the virtualized environment
  • Disrupt operations of all managed ESXi hosts

Given vCenter Server’s central role in managing virtual infrastructure, successful exploitation represents a severe risk to the entire data center environment. The active exploitation status elevates the urgency for immediate remediation.

Remediation

VMware has released hotfixes for affected versions. Apply the vendor-supplied patch immediately. If patching is not immediately feasible:

  1. Restrict network access to the Syslog service (default port 514) to trusted hosts only
  2. Place vCenter Server behind a firewall with strict allowlists
  3. Monitor Syslog traffic for anomalous directory traversal patterns
  4. Review recent access logs for indicators of compromise
  5. Isolate vCenter Server from internet-facing networks entirely

Organizations without an immediate patch window should treat this as a high-priority incident and implement compensating controls until the hotfix can be deployed.

For broader context on actively exploited infrastructure vulnerabilities, see CISA Flags SolarWinds, Ivanti, and Workspace One and CISA Adds Actively Exploited VMware Aria Operations.

Security Insight

This vulnerability follows a concerning pattern of VMware infrastructure products becoming prime targets for state-sponsored and financially motivated threat actors alike. The focus on syslog infrastructure, a service many organizations leave exposed and under-monitored, reflects a broader shift toward attacking management-plane services rather than edge devices. The CISA KEV listing within days of disclosure demonstrates how quickly weaponized exploits propagate once infrastructure-level flaws become public.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.