News Room
16
Share
Critical VMware vCenter Directory Traversal Flaw Under Active Exploitation
criticalZero-Day Exploits

Critical VMware vCenter Directory Traversal Flaw Under Active Exploitation

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Server is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to achieve arbitrary code execution.

20 September 2026Last updated 20 September 20264 min readKudelski Security Research Center
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-59310
Source:
Kudelski Security Research Center
Read Time:
4 min

Executive Summary

Security researchers have identified a critical directory traversal vulnerability, tracked as CVE-2026-59310, affecting multiple versions of VMware vCenter Server. With a CVSSv3 score of 9.8, this vulnerability enables unauthenticated, remote attackers to execute arbitrary code on the underlying operating system. Reports confirm that this flaw is currently being exploited in the wild, necessitating immediate patching for all affected enterprise environments.

Threat Analysis

The vulnerability resides within the VMware vCenter Syslog server component. By sending specially crafted requests, an attacker can bypass security controls to perform directory traversal, ultimately leading to full system compromise. The active exploitation indicates that threat actors are prioritizing this vector to gain a foothold in virtualized data centers, likely for lateral movement or data exfiltration.

Technical Details

CVE-2026-59310 allows an attacker to manipulate file paths within the Syslog server's processing logic. Because the service runs with elevated privileges, successful exploitation grants the attacker root-level access to the vCenter appliance. This bypasses standard authentication mechanisms, allowing for the deployment of web shells or secondary payloads without requiring valid credentials.

Attribution Assessment

While specific threat actor attribution remains under investigation, the nature of the exploit—targeting critical infrastructure management software—is consistent with advanced persistent threat (APT) groups focused on espionage and long-term persistence within high-value corporate and government networks.

Implications

Organizations utilizing VMware Cloud Foundation, vSphere Foundation, or standalone vCenter instances are at high risk. A successful breach could lead to the total compromise of the virtualized environment, allowing attackers to access sensitive virtual machines, modify network configurations, and potentially disrupt critical business operations.

Recommendations

  1. Immediate Patching: Apply the latest security updates provided by VMware for vCenter versions 9.1.x.x, 9.0.x.x, and 8.0 U3k.
  2. Network Segmentation: Restrict access to the vCenter management interface to trusted administrative subnets only.
  3. Log Monitoring: Review system logs for anomalous file access patterns or unexpected process execution originating from the Syslog service.
  4. Incident Response: Assume potential compromise if the vCenter instance was exposed to the public internet prior to patching.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo