


Perceptive Security
SOC/SIEM Consultancy

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to exe…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 17:06:28
Source:
nvd.nist.gov
Cloud & Virtualization, Zero-Day Vulnerabilities
VMware vCenter contains a directory traversal vulnerability in its Syslog server component. A malicious actor with network access to vCenter can exploit this vulnerability to execute arbitrary code on the affected system. The vulnerability does not appear to require authentication, making it particularly dangerous in environments where vCenter is network-accessible. This is a critical vulnerability affecting VMware vCenter infrastructure, which is widely used in enterprise virtualization environments. The issue is currently awaiting full analysis on NVD. Broadcom has published a security advisory addressing the vulnerability. Organizations running VMware vCenter should apply patches or mitigations as soon as they become available.
Technical details
Mitigation steps:
Affected products:
VMware vCenter
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59310
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
