CVE-2026-59310 โ VMware vCenter Directory Traversal
CVE-2026-59310 is a directory-traversal vulnerability in Broadcom VMware vCenter Server, rated CVSS 9.8. A malicious actor with network access can exploit it to execute arbitrary code on the management server, and threat actors have begun actively exploiting it for persistent remote access to vCenter management infrastructure, per researcher telemetry from QUIRSO.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-59310 |
| Type | Directory traversal leading to remote code execution |
| Product | Broadcom VMware vCenter Server |
| CVSS | 9.8 (Critical) |
| Access | Network (unauthenticated per vendor severity) |
| Exploitation status | Exploited in the wild (QUIRSO telemetry, disclosed 2026-08-12) |
| Remediation | Patches shipped by Broadcom; apply immediately to reachable vCenter instances |
Context
vCenter is the control plane for VMware virtualised estates, making this a high-value target: persistent access to vCenter effectively means persistent access to every workload on the platform. The disclosure follows the week's theme of internet-exposed management surfaces being the dominant attack surface (alongside the afd.sys zero-day and Fortinet appliance targeting). Australian and NZ organisations running vCenter should treat this as an urgent patch โ unpatched management consoles are a classic first step in ransomware and data-theft operations.
Related Pages
- Lazarus Exploits Windows Zero Day To Gain System Access And Deploy Backdoor โ the same week's zero-day exploitation trend
- Cve 2026 68820 Afd Sys Winsock Uaf โ afd.sys WinSock zero-day
Sources: raw/digests/Cyber-Digest-2026-08-13