Database/Control plane, storage & DevOps
VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server letting
Impact
Directory traversal in the vCenter syslog server letting an unauthenticated network attacker execute arbitrary code on vCenter. Chained with the authentication bypass in the same advisory, this is the full remote-takeover pair - and it is being exploited in the wild.
Who can reach it
Network access to vCenter. Unauthenticated.
What to do
Apply the Broadcom fix immediately. vCenter patch and restart. Assume compromise on any vCenter that was network-exposed and unpatched during the exploitation window; rotate vCenter and ESXi credentials afterwards.
References
Related entries
- Gitea: unauthenticated remote code execution via the diffpatch API installing Git hooksCVE-2026-60004 · Gitea (diffpatch API / Git hook installation)Critical
- JetBrains TeamCity: Deserialization in the agent polling protocolCVE-2026-63077 · JetBrains TeamCityCritical
- Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-basedCVE-2026-65791 · Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+)Critical
- Windows Services for NFS: use-after-free in the ONCRPC XDR driver allows unauthenticated remote code executionCVE-2026-69595 · Windows Services for NFS (ONCRPC XDR driver)Critical
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCVE-2026-72217 · Linux SUNRPC (xdr_buf_to_bvec, nfsd write path)Critical
- Linux VXLAN driver (transmit-path header pulls): `vxlan_xmit()`, `arp_reduce()` and `vxlan_mdb_entry_skb_get()`CVE-2026-74474 · Linux VXLAN driver (transmit-path header pulls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.