
Critical VMware vCenter Directory Traversal Flaw Under Active Exploitation
A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Server is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to achieve arbitrary code execution.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-59310
- Source:
- Kudelski Security Research Center
- Read Time:
- 4 min
Executive Summary
Security researchers have identified a critical directory traversal vulnerability, tracked as CVE-2026-59310, affecting multiple versions of VMware vCenter Server. With a CVSSv3 score of 9.8, this vulnerability enables unauthenticated, remote attackers to execute arbitrary code on the underlying operating system. Reports confirm that this flaw is currently being exploited in the wild, necessitating immediate patching for all affected enterprise environments.
Threat Analysis
The vulnerability resides within the VMware vCenter Syslog server component. By sending specially crafted requests, an attacker can bypass security controls to perform directory traversal, ultimately leading to full system compromise. The active exploitation indicates that threat actors are prioritizing this vector to gain a foothold in virtualized data centers, likely for lateral movement or data exfiltration.
Technical Details
CVE-2026-59310 allows an attacker to manipulate file paths within the Syslog server's processing logic. Because the service runs with elevated privileges, successful exploitation grants the attacker root-level access to the vCenter appliance. This bypasses standard authentication mechanisms, allowing for the deployment of web shells or secondary payloads without requiring valid credentials.
Attribution Assessment
While specific threat actor attribution remains under investigation, the nature of the exploit—targeting critical infrastructure management software—is consistent with advanced persistent threat (APT) groups focused on espionage and long-term persistence within high-value corporate and government networks.
Implications
Organizations utilizing VMware Cloud Foundation, vSphere Foundation, or standalone vCenter instances are at high risk. A successful breach could lead to the total compromise of the virtualized environment, allowing attackers to access sensitive virtual machines, modify network configurations, and potentially disrupt critical business operations.
Recommendations
- Immediate Patching: Apply the latest security updates provided by VMware for vCenter versions 9.1.x.x, 9.0.x.x, and 8.0 U3k.
- Network Segmentation: Restrict access to the vCenter management interface to trusted administrative subnets only.
- Log Monitoring: Review system logs for anomalous file access patterns or unexpected process execution originating from the Syslog service.
- Incident Response: Assume potential compromise if the vCenter instance was exposed to the public internet prior to patching.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Cisco Zero-Day Exploitation Wave: ISE and Email Gateway Under Attack

Critical Zero-Day Exploitation Surge: Cisco Email Gateway and Android Pixel Flaws Under Attack

