Home Β· Wiki Β· Vulnerabilities & CVEs
type: cve Β· created: 2026-09-16 Β· updated: 2026-09-16 Β· tags: [cve, exploited] Β· confidence: high Β· severity: critical Β· affected_sectors: [global] Β· au_impact: false

A directory traversal flaw in the VMware vCenter Syslog server. NVD scores it 9.8 (Critical, CVSS 3.1) and its description states that a malicious actor with network access to vCenter may exploit it to execute arbitrary code.

Attribute Detail
CVE CVE-2026-59310
CVSS 9.8 (CVSS 3.1) (Critical)
Vendor / product VMware / vCenter Server (Syslog server)
Reported 2026-09-16

Virtualisation and platform teams should treat the patch as an emergency change: vCenter is the management plane for an entire virtual estate, so root-level access from a network-reachable endpoint converts directly into control of every guest it hosts and the snapshots and backups they depend on. Ransomware operators have consistently treated hypervisor management as a force multiplier β€” control of vCenter is what allows a victim's recovery copies to be destroyed rather than merely encrypted β€” so verify no instance is reachable from an untrusted network while the fix is outstanding.