Broadcom VMware vCenter Path Traversal Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Fixed in 8.0, 9.0.2.0100, 9.1.0.0300 — upgrade to this release or later.
  • CVEs: CVE-2026-59310.

What it is

CVE-2026-59310 is a directory traversal vulnerability in the Syslog server component of VMware vCenter. An attacker with network access to vCenter can exploit path traversal in the Syslog service to write files outside the intended directory, resulting in arbitrary code execution.

The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates this is exploitable over the network with low attack complexity, requires no privileges, and needs no user interaction. The impact scores are full compromise across confidentiality, integrity and availability, consistent with a path to arbitrary code execution on the vCenter server itself.

This sits on the management plane — vCenter is the central control point for vSphere environments — so code execution here gives an attacker a foothold with visibility and potential control over the wider virtual infrastructure it manages.

The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-08-18, so it is known to be exploited.

What to do

  • Patch to the fixed releases identified by Broadcom: 8.0, 9.0.2.0100, or 9.1.0.0300, depending on your current vCenter version line.
  • Prioritise this patch above routine maintenance windows given the KEV listing and the unauthenticated, network-reachable attack path.
  • Restrict network access to the vCenter Syslog server to trusted management networks only; it should not be reachable from general user or workload segments.
  • Review vCenter logs for unexpected file writes or process activity around the Syslog service as part of triage, particularly for instances that have been internet- or broadly network-accessible.
  • Confirm the exact build number after patching against Broadcom’s advisory, as vCenter versioning across 8.0 and 9.x lines can be granular.

For leadership 🧭

Executive summary. An unauthenticated attacker with network access to vCenter can achieve arbitrary code execution on the platform that manages your entire virtual infrastructure, and this is already being exploited in the wild. Patch immediately, ahead of any routine maintenance schedule.

Why it matters:

  • vCenter is the management plane for vSphere, so code execution here can give an attacker visibility into and potential control over every host and VM it manages, not just the vCenter appliance itself.
  • The flaw sits in the Syslog server component and requires no authentication, no privileges and no user interaction, so any device with network reach to that service is a potential attack path.
  • CISA added this to its Known Exploited Vulnerabilities catalogue on 2026-08-18, meaning it is confirmed to be under active exploitation, not just theoretically dangerous.
  • The CVSS score of 9.8 with full confidentiality, integrity and availability impact reflects a direct route to full server compromise via path traversal file writes.

Now / Next / Later:

  • Now: Identify every vCenter instance in the estate and check its version against the fixed releases (8.0, 9.0.2.0100, 9.1.0.0300) to establish exposure.
  • Next: Patch all affected vCenter instances to the appropriate fixed build ahead of routine maintenance windows, and restrict network access to the Syslog server to trusted management segments only.
  • Later: Establish standing network segmentation so vCenter’s Syslog service is never reachable from general user or workload networks, and build a process to check vCenter builds against Broadcom advisories on a regular cadence.

Source