Critical CVE-2026-59310 — A CVSS 9.8 directory traversal in vCenter's syslog server lets anyone with network access run code, and ransomware crews are using it. Fixed in vCenter 8.0 U3k, 9.0.2.0100 and 9.1.0.0300. How to check and protect your vSphere environment.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Anyone who can reach vCenter on the network can exploit a directory traversal in its built-in syslog server to run code. CISA lists it as used in ransomware campaigns, which makes sense, because vCenter is the key to encrypting every VM at once. Upgrade to vCenter 8.0 U3k, 9.0.2.0100 or 9.1.0.0300, and make sure vCenter is only reachable from a management network.
| CVE | CVE-2026-59310 |
|---|---|
| Component | VMware vCenter Server, built-in Syslog server |
| Type | Directory traversal → remote code execution |
| CVSS 3.1 | 9.8 Critical |
| Auth needed | None; network access to vCenter |
| Fixed in | vCenter 8.0 U3k · 9.0.2.0100 · 9.1.0.0300 (also bundled in VCF / vSphere Foundation / Telco Cloud updates) |
| Exploited? | Yes, CISA KEV 2026-08-18, known ransomware use |
vCenter includes a syslog receiver so hosts can send it their logs. Broadcom’s advisory says that receiver doesn’t properly restrict file paths, so a crafted message can write outside the intended log directory, and with the right target that becomes arbitrary code execution on the vCenter appliance.
Ransomware groups love vCenter because from it they can shut down and encrypt every VM and datastore in one go, or push malicious changes to every ESXi host. That’s why CISA’s “known ransomware campaign use” flag on this one matters.
In the vSphere Client: click the vCenter name → Summary, or log in to the VAMI at https://<vcenter>:5480 → Summary. From the appliance shell: vpxd -v.
| vCenter line | Fixed release |
|---|---|
| 8.0 | 8.0 Update 3k |
| 9.0 | 9.0.2.0100 |
| 9.1 | 9.1.0.0300 |
VMware Cloud Foundation (5.x, 9.0, 9.1), vSphere Foundation and Telco Cloud Platform/Infrastructure all include vCenter and are affected too. Apply the corresponding async patch for your bundle. vCenter 7.0 reached end of general support in 2025; if you’re still on it, check Broadcom’s advisory for whether a fix exists for your entitlement.
execInstalledOnly setting so a compromised vCenter can’t simply run arbitrary binaries on hosts./tmp, new local accounts (/etc/passwd on the appliance), or new SSO users/groups with admin rights.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.