chiprook
← Security
SecuritySeptember 20, 2026, 02:00

vCenter Syslog directory traversal CVE-2026-59310 exploited for RCE

A directory traversal in vCenter Syslog (CVE-2026-59310) allows unauthenticated RCE. Broadcom fixed it on July 29, 2026 in VMSA-2026-0006; attacks began August 3, and by August 10 361 victim IPs in 47 countries were recorded. CISA added it to KEV over ransomware use.

vCenter Syslog directory traversal CVE-2026-59310 exploited for RCE
#Broadcom#VMware#VCenter#CISA
Read next
Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts

Security

Samsung and LG to remove botnet apps from smart TV stores

Security

CrowdSec confirms source code stolen in supply chain attack