9.8

CVE-2026-59310

Warnung
Medienbericht

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ vCenter Server Version < 8.0
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update -
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update a
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update b
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update c
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1a
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1b
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1c
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1d
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update1e
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2a
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2b
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2c
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2d
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update2e
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3a
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3b
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3c
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3d
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3e
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3g
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3h
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3i
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version 8.0 Update update3j
   VMware ≫ Telco Cloud Infrastructure Version 3.0
   VMware ≫ Telco Cloud Platform Version >= 3.0 <= 5.2
VMware ≫ vCenter Server Version >= 9.0 < 9.0.2.0100
   VMware ≫ Cloud Foundation Version -
   VMware ≫ Vsphere Foundation Version -
VMware ≫ vCenter Server Version >= 9.1 < 9.1.0.0300
   VMware ≫ Cloud Foundation Version -
   VMware ≫ Vsphere Foundation Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

18.08.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Broadcom VMware vCenter Path Traversal Vulnerability

Schwachstelle

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.41% 0.827
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
VMware 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.09.2026 06:03
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
15.09.2026 14:40
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.09.2026 19:19
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
19.08.2026 13:49
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
19.08.2026 08:34
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 16:16
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 13:00
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.08.2026 18:57
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.08.2026 08:42
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
12.08.2026 11:55
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.07.2026 20:25
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.07.2026 14:55
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Vendor Advisory
https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
Third Party Advisory
https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
US Government Resource