🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-59310.

What it is

CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter. It has a CVSS score of 9.8 (Critical), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — meaning it is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and results in full compromise of confidentiality, integrity and availability.