vCenter Syslog directory traversal CVE-2026-59310 exploited for RCE
A directory traversal in vCenter Syslog (CVE-2026-59310) allows unauthenticated RCE. Broadcom fixed it on July 29, 2026 in VMSA-2026-0006; attacks began August 3, and by August 10 361 victim IPs in 47 countries were recorded. CISA added it to KEV over ransomware use.
- Broadcom fixed CVE-2026-59310 on July 29, 2026; only update, no workaround
- Attacks began 5 days after patch; by August 10, 361 IPs in 47 countries
- CISA flagged the flaw as used in ransomware campaigns
- ZoomEye: 1.42M records for app="VMware" and 239K for app="Citrix NetScaler"
Read next
Security