• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-59310: pre-auth remote code execution in Broadcom VMware vCenter

An attacker with network access can exploit a directory traversal vulnerability in VMware vCenter to execute arbitrary code (CVE-2026-59310). Affected products include multiple vCenter and related Cloud Foundation, vSphere, Telco Cloud branches listed in vendor advisories; specific fixed releases exist for some 8.x and 9.x vCenter builds while other branches remain affected. The flaw requires only network access to vCenter and no valid credentials, allowing remote compromise of vulnerable instances.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.02565
CWE
CWE-22
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a fast remediation deadline, so prioritize patching or implementing vendor mitigations immediately.

What is CVE-2026-59310?

An attacker with network access can exploit a directory traversal vulnerability in VMware vCenter to execute arbitrary code (CVE-2026-59310). Affected products include multiple vCenter and related Cloud Foundation, vSphere, Telco Cloud branches listed in vendor advisories; specific fixed releases exist for some 8.x and 9.x vCenter builds while other branches remain affected. The flaw requires only network access to vCenter and no valid credentials, allowing remote compromise of vulnerable instances. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Broadcom VMware vCenter are affected?

BRANCHAFFECTEDFIXED
Cloud Foundation 9.x9.1.x.x
Cloud Foundation 9.x9.0.x.x
Cloud Foundation 5.x5.x
vSphere Foundation 9.x9.1.x.x
vSphere Foundation 9.x9.0.x.x
vCenter 9.x9.1.x.x – before 9.1.0.03009.1.0.0300
vCenter 9.x9.0.x.x – before 9.0.2.01009.0.2.0100
vCenter 8.x8.0 – before 8.0 U3k8.0 U3k
Telco Cloud Infrastructure 3.x3.0
Telco Cloud Platform 5.x5.1.x

Is CVE-2026-59310 being exploited?

CISA added CVE-2026-59310 to the Known Exploited Vulnerabilities catalog on 2026-08-18, and U.S. federal agencies had a fix-by date of 2026-08-21. Public exploit code is also available.

How to fix CVE-2026-59310

  1. Apply vendor updates: upgrade vCenter 9.1 to 9.1.0.0300 or later, 9.0 to 9.0.2.0100 or later, and 8.0 to 8.0 U3k or later where listed as fixed.
  2. If you cannot patch immediately, follow VMware's mitigation guidance and restrict network exposure of vCenter to trusted management networks.
  3. Monitor vCenter logs and forensics indicators for signs of exploitation and review access from external networks.
  4. Implement network controls such as firewall rules and VPN-only access to limit who can reach vCenter services.

Frequently asked questions

Is CVE-2026-59310 being actively exploited?

Yes: CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog on 2026-08-18 with a required remediation date of 2026-08-21, and public exploit code is available.

Which VMware vCenter versions are affected by CVE-2026-59310?

Multiple VMware vCenter branches are affected across 8.x and 9.x and related Cloud Foundation, vSphere, and Telco Cloud products; the vendor lists specific affected builds and which releases contain fixes.

Is there a patch for CVE-2026-59310?

Yes: VMware published fixed builds for some vCenter releases, including 9.1.0.0300, 9.0.2.0100, and 8.0 U3k; apply the vendor updates for your specific branch.

Does CVE-2026-59310 require authentication?

No: the vulnerability can be exploited with only network access to VMware vCenter and does not require valid credentials.

References