EXPOSURES › CVE-2026-59310
CVE-2026-59310
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.
A path traversal vulnerability in the VMware vCenter Syslog server allowed unauthenticated attackers with network access to execute arbitrary code and deploy reverse SSH tools for persistent access. DIB organizations must ensure vCenter is patched and network-isolated, as this flaw was actively exploited in the wild to gain initial footholds before attackers deployed further tooling.
Shame score — A maximum-severity path traversal flaw was actively exploited in the wild by unauthenticated attackers to execute arbitrary code and establish persistent backdoors, indicating negligent patching and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Clarity Broadcom |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |