9.8

CVE-2026-59310

Warnung
Medienbericht

vCenter directory-traversal vulnerability

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwarevCenter Server Version < 8.0
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Update-
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updatea
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateb
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updatec
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1a
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1b
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1c
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1d
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate1e
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2a
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2b
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2c
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2d
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate2e
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3a
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3b
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3c
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3d
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3e
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3g
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3h
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3i
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version8.0 Updateupdate3j
   VMwareTelco Cloud Infrastructure Version3.0
   VMwareTelco Cloud Platform Version >= 3.0 <= 5.2
VMwarevCenter Server Version >= 9.0 < 9.0.2.0100
   VMwareCloud Foundation Version-
   VMwareVsphere Foundation Version-
VMwarevCenter Server Version >= 9.1 < 9.1.0.0300
   VMwareCloud Foundation Version-
   VMwareVsphere Foundation Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

18.08.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Broadcom VMware vCenter Path Traversal Vulnerability

Schwachstelle

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.41% 0.827
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
VMware 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
19.08.2026 13:49
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
19.08.2026 08:34
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 16:16
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 13:00
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.08.2026 18:57
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.08.2026 08:42
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
12.08.2026 11:55
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.07.2026 20:25
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
30.07.2026 14:55
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Vendor Advisory
https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
Third Party Advisory
https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
US Government Resource