Vulnerability
Published 2026-08-18
Verified 2026-09-19

VMware vCenter Syslog path traversal RCE (CVE-2026-59310); CVSS 9.8 — CISA KEV ransomware Known

Broadcom VMSA-2026-0006 (29 July 2026; updated 19 August) covers CVE-2026-59310, a Critical directory-traversal flaw in the VMware vCenter Syslog server. A malicious actor with network access to vCenter can execute arbitrary code; Broadcom rates maximum CVSSv3 9.8; NVD CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No workarounds — apply fixed builds per the VMSA response matrix / FAQ (brcm.tech/vmsa-2026-0006). CISA added the CVE to KEV on 18 August 2026 (FCEB due 21 August) after QUIRSO reported 361+ compromised IPs across 47 countries with reverse-SSH persistence. UPDATE 15 September 2026 (BleepingComputer; CISA KEV catalog field knownRansomwareCampaignUse=Known): CISA now flags the flaw as used in ransomware campaigns; Shadowserver still tracks 450+ internet-exposed vCenter instances. Treat unpatched vCenter as emergency. Primary: Broadcom VMSA-2026-0006; CISA KEV; wire: BleepingComputer 15 Sep.

Product
Broadcom VMware vCenter Server (Syslog server); also listed under VMSA-2026-0006 product family
Versions
Affected/fixed builds: see Broadcom VMSA-2026-0006.2 response matrix (Issue date 2026-07-29). Patch per vendor FAQ https://brcm.tech/vmsa-2026-0006
CVSS
Exploited in Australia?
unknown
Patch to
Install Broadcom-fixed vCenter builds from VMSA-2026-0006 response matrix immediately; no workaround; prioritise internet-facing vCenter

Primary: Broadcom VMSA-2026-0006 — vCenter Syslog path traversal (CVE-2026-59310) · Vendor: Broadcom Security Advisory 38017 (VMSA-2026-0006) · CVE: CVE-2026-59310 · CISA KEV — CVE-2026-59310 (ransomware Known); BleepingComputer 15 Sep wire

vulnerabilities cloud network