{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-02T09:07:25.339","vulnerabilities":[{"cve":{"id":"CVE-2026-59310","sourceIdentifier":"security@vmware.com","published":"2026-07-30T13:16:53.993","lastModified":"2026-08-19T04:17:24.940","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code."}],"affected":[{"source":"security@vmware.com","affectedData":[{"vendor":"VMware","product":"Cloud Foundation","defaultStatus":"unaffected","versions":[{"version":"9.1.x.x","status":"affected"},{"version":"9.0.x.x","status":"affected"},{"version":"5.x","status":"affected"}]},{"vendor":"VMware","product":"vSphere Foundation","defaultStatus":"unaffected","versions":[{"version":"9.1.x.x","status":"affected"},{"version":"9.0.x.x","status":"affected"}]},{"vendor":"VMware","product":"vCenter","defaultStatus":"unaffected","versions":[{"version":"9.1.x.x","lessThan":"9.1.0.0300","versionType":"custom","status":"affected"},{"version":"9.0.x.x","lessThan":"9.0.2.0100","versionType":"custom","status":"affected"},{"version":"8.0","lessThan":"8.0 U3k","versionType":"custom","status":"affected"}]},{"vendor":"VMware","product":"Telco Cloud Infrastructure","defaultStatus":"unaffected","versions":[{"version":"3.0","status":"affected"}]},{"vendor":"VMware","product":"Telco Cloud Platform","defaultStatus":"unaffected","versions":[{"version":"5.1.x","status":"affected"},{"version":"5.0.x","status":"affected"},{"version":"4.x","status":"affected"},{"version":"3.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@vmware.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-29T00:00:00+00:00","id":"CVE-2026-59310","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-18","cisaActionDue":"2026-08-21","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"Broadcom VMware vCenter Path Traversal Vulnerability","weaknesses":[{"source":"security@vmware.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0","matchCriteriaId":"6B17478A-E6D9-4C6B-8810-7E1BC9E7392F"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*","matchCriteriaId":"CC974CA1-88D3-42E4-BF1F-28870F8171B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*","matchCriteriaId":"EFE63984-F69B-4593-9AEC-D179D6D98B08"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*","matchCriteriaId":"34D1F3B3-8E3F-4E4D-8EE6-2F593663B5CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*","matchCriteriaId":"16F3D992-9F48-4604-9AAF-DC2D1CE98BE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*","matchCriteriaId":"C745A7E6-4760-48CD-B7C4-1C2C20217F21"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*","matchCriteriaId":"A5522514-8ED9-45DB-9036-33FE40D77E7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*","matchCriteriaId":"8C27C660-E917-4944-8B4C-41D9622B76D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*","matchCriteriaId":"56CFB469-B3E6-4503-A47C-D18206D4D19A"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*","matchCriteriaId":"67024A43-9E13-4F4E-B711-731792DA3840"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:*","matchCriteriaId":"1188E9D6-53AD-40D0-8146-3728D071008D"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*","matchCriteriaId":"604F559F-1775-4F29-996E-9079B99345B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*","matchCriteriaId":"61DC9400-5AEE-49AC-9925-0A96E32BD8C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*","matchCriteriaId":"98C1B77E-AB0E-4E8A-8294-2D3D230CDF9B"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*","matchCriteriaId":"8EC8BEF1-7908-46C0-841A-834778D1A863"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:*","matchCriteriaId":"89D5A7F9-3183-4EE7-828C-13BB9169E199"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:*","matchCriteriaId":"9EB94E5F-9AFB-471C-887C-4C53B5169347"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:*","matchCriteriaId":"D8C5E404-9A83-472C-AE97-25DAE332C327"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:*","matchCriteriaId":"78312C9E-4653-4C79-9886-A7A63DB98262"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:*","matchCriteriaId":"722B1899-0229-4BEA-94C4-1E475406E7AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3c:*:*:*:*:*:*","matchCriteriaId":"E1EA338E-4263-42A9-8E91-C3D91A7F8AD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3d:*:*:*:*:*:*","matchCriteriaId":"3EFDF451-E83B-4340-BF06-AA017B042841"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3e:*:*:*:*:*:*","matchCriteriaId":"20D28DF8-BAD2-4613-9325-A55B06FB1F21"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3g:*:*:*:*:*:*","matchCriteriaId":"FF925343-3889-46EC-87C5-82B8C3DC33ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3h:*:*:*:*:*:*","matchCriteriaId":"D9BD9CEF-D37E-45AF-883F-120C32849E14"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3i:*:*:*:*:*:*","matchCriteriaId":"1D402845-1C50-40CE-BAA2-CDD5615B660D"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:8.0:update3j:*:*:*:*:*:*","matchCriteriaId":"9552133F-9C74-4368-857A-BAFA182BE8EA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:vmware:telco_cloud_infrastructure:3.0:*:*:*:*:*:*:*","matchCriteriaId":"D11103A7-6AB5-4E78-BE11-BC2A04A09F19"},{"vulnerable":false,"criteria":"cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndIncluding":"5.2","matchCriteriaId":"320FDFEE-22D1-4650-B177-BF7B1E750D45"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0","versionEndExcluding":"9.0.2.0100","matchCriteriaId":"45C693CF-0995-4332-9B1E-018EBCDAF83A"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*","versionStartIncluding":"9.1","versionEndExcluding":"9.1.0.0300","matchCriteriaId":"C014E906-B622-424E-BFF9-660187C73C54"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:vmware:cloud_foundation:-:*:*:*:*:*:*:*","matchCriteriaId":"31A7BB38-3238-413E-9736-F1A165D40867"},{"vulnerable":false,"criteria":"cpe:2.3:a:vmware:vsphere_foundation:-:*:*:*:*:*:*:*","matchCriteriaId":"03AD0AB7-45A3-4DC7-923D-1166346EEA12"}]}]}],"references":[{"url":"https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017","source":"security@vmware.com","tags":["Vendor Advisory"]},{"url":"https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]},{"url":"https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}}]}