Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-59310: VMware vCenter Syslog Path Traversal RCE, Used by Ransomware

Critical CVE-2026-59310 — A CVSS 9.8 directory traversal in vCenter's syslog server lets anyone with network access run code, and ransomware crews are using it. Fixed in vCenter 8.0 U3k, 9.0.2.0100 and 9.1.0.0300. How to check and protect your vSphere environment.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Anyone who can reach vCenter on the network can exploit a directory traversal in its built-in syslog server to run code. CISA lists it as used in ransomware campaigns, which makes sense, because vCenter is the key to encrypting every VM at once. Upgrade to vCenter 8.0 U3k, 9.0.2.0100 or 9.1.0.0300, and make sure vCenter is only reachable from a management network.

CVECVE-2026-59310
ComponentVMware vCenter Server, built-in Syslog server
TypeDirectory traversal → remote code execution
CVSS 3.19.8 Critical
Auth neededNone; network access to vCenter
Fixed invCenter 8.0 U3k · 9.0.2.0100 · 9.1.0.0300 (also bundled in VCF / vSphere Foundation / Telco Cloud updates)
Exploited?Yes, CISA KEV 2026-08-18, known ransomware use

What the bug is

vCenter includes a syslog receiver so hosts can send it their logs. Broadcom’s advisory says that receiver doesn’t properly restrict file paths, so a crafted message can write outside the intended log directory, and with the right target that becomes arbitrary code execution on the vCenter appliance.

Ransomware groups love vCenter because from it they can shut down and encrypt every VM and datastore in one go, or push malicious changes to every ESXi host. That’s why CISA’s “known ransomware campaign use” flag on this one matters.

Am I affected?

In the vSphere Client: click the vCenter name → Summary, or log in to the VAMI at https://<vcenter>:5480 → Summary. From the appliance shell: vpxd -v.

vCenter lineFixed release
8.08.0 Update 3k
9.09.0.2.0100
9.19.1.0.0300

VMware Cloud Foundation (5.x, 9.0, 9.1), vSphere Foundation and Telco Cloud Platform/Infrastructure all include vCenter and are affected too. Apply the corresponding async patch for your bundle. vCenter 7.0 reached end of general support in 2025; if you’re still on it, check Broadcom’s advisory for whether a fix exists for your entitlement.

How to patch

  1. Take a file-based backup of vCenter (VAMI → Backup) and a snapshot of the vCenter VM (powered-off snapshot if you can).
  2. VAMI → Update → check the online repository (or mount the patch ISO) → stage and install.
  3. Confirm the build afterwards and remove the snapshot once you’re happy.

Hardening

  • vCenter and ESXi management should live on a dedicated management VLAN reachable only from admin workstations or a jump host, never from the general LAN and never from the internet.
  • If you don’t use vCenter as a syslog target, point ESXi hosts at a dedicated log server instead, and firewall syslog ports (UDP/TCP 514, TCP 1514) on vCenter to only the hosts that need them.
  • Enable ESXi lockdown mode and the execInstalledOnly setting so a compromised vCenter can’t simply run arbitrary binaries on hosts.
  • Keep immutable or offline backups of your VMs. If vCenter falls, that’s what saves you.

Signs of compromise

  • Unexpected files in vCenter’s web directories or /tmp, new local accounts (/etc/passwd on the appliance), or new SSO users/groups with admin rights.
  • New SSH keys on ESXi hosts, SSH unexpectedly enabled, or VMs being powered off in bulk.
  • If you find any of it, treat it as an active ransomware incident: isolate management networks and call incident response before attackers reach the encryption stage.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories