Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [cve, vmware, vcenter, broadcom, directory-traversal, exploited-in-the-wild, remote-code-execution] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, healthcare, education] ยท au_impact: true

CVE-2026-59310 โ€” VMware vCenter Directory Traversal

CVE-2026-59310 is a directory-traversal vulnerability in Broadcom VMware vCenter Server, rated CVSS 9.8. A malicious actor with network access can exploit it to execute arbitrary code on the management server, and threat actors have begun actively exploiting it for persistent remote access to vCenter management infrastructure, per researcher telemetry from QUIRSO.

Vulnerability Details

Attribute Detail
CVE CVE-2026-59310
Type Directory traversal leading to remote code execution
Product Broadcom VMware vCenter Server
CVSS 9.8 (Critical)
Access Network (unauthenticated per vendor severity)
Exploitation status Exploited in the wild (QUIRSO telemetry, disclosed 2026-08-12)
Remediation Patches shipped by Broadcom; apply immediately to reachable vCenter instances

Context

vCenter is the control plane for VMware virtualised estates, making this a high-value target: persistent access to vCenter effectively means persistent access to every workload on the platform. The disclosure follows the week's theme of internet-exposed management surfaces being the dominant attack surface (alongside the afd.sys zero-day and Fortinet appliance targeting). Australian and NZ organisations running vCenter should treat this as an urgent patch โ€” unpatched management consoles are a classic first step in ransomware and data-theft operations.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13