logo

CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw

ID: e07026ea-4f4b-5819-a988-a94fcb712ffb

STIX ID: report--e07026ea-4f4b-5819-a988-a94fcb712ffb

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Divya

...
...

Critical path traversal vulnerability CVE-2026-59310 in VMware vCenter Syslog Server (CWE-22) enables unauthenticated remote code execution and has been assigned CVSS 9.8; Broadcom released fixes on July 29, 2026 and CISA added the flaw to its KEV Catalog with an August 21 remediation deadline for federal agencies. Exploitation was observed in the wild within days of disclosure, with attackers reportedly using reverse SSH for persistence and researchers finding hundreds of potentially affected public-facing systems; organizations are advised to prioritize patching internet-exposed vCenter instances, perform forensic triage, and treat unpatched systems as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.