GPU VulnDB

Database/Control plane, storage & DevOps

VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server letting

CVE-2026-59310Control plane, storage & DevOpsKnown exploitedcurated

Impact

Directory traversal in the vCenter syslog server letting an unauthenticated network attacker execute arbitrary code on vCenter. Chained with the authentication bypass in the same advisory, this is the full remote-takeover pair - and it is being exploited in the wild.

Who can reach it

Network access to vCenter. Unauthenticated.

What to do

Apply the Broadcom fix immediately. vCenter patch and restart. Assume compromise on any vCenter that was network-exposed and unpatched during the exploitation window; rotate vCenter and ESXi credentials afterwards.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.