Knox CVE Database
/
CVE-2026-59310
Critical
9.8

CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Added to the CISA KEV catalog:
August 18, 2026

Overview

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Vulnerability details

Affected vendor
Broadcom
Affected product
VMware vCenter
Weakness type (CWE)
CWE-22

VMware vCenter contains a path traversal vulnerability (CWE-22) in its Syslog server component. Path traversal flaws arise when user-supplied input containing directory separator sequences is processed without adequate sanitization, allowing the application to operate on files outside the intended directory boundary. In vCenter's case, the Syslog server accepts attacker-controlled input that can carry traversal sequences, causing the server to read or write files at arbitrary locations on the underlying host filesystem. Broadcom rates this issue at Critical severity.


An attacker with network access to the vCenter instance can send crafted requests to the Syslog server containing path-traversal sequences, requiring no authentication and no user interaction. Successful exploitation allows the attacker to write attacker-controlled content to arbitrary filesystem locations, which in turn produces arbitrary code execution on the vCenter host. Third-party incident response reporting documents active exploitation in the wild, with attackers deploying reverse SSH tooling post-compromise to maintain persistent access to affected systems.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for unexpected outbound SSH or reverse-tunnel connections originating from the vCenter host process, particularly to external IP addresses with no corresponding administrative session. Healthy vCenter hosts do not initiate reverse SSH to external infrastructure.
  • Audit the vCenter host filesystem for newly created or modified files in directories outside the expected Syslog working path, especially executable files, cron entries, or scripts written during or after periods of Syslog server activity.
  • Review network flow logs for inbound connections to the vCenter Syslog server port from sources outside the defined management network. Connections from internet-routable addresses to this service are anomalous and warrant immediate investigation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 21, 2026

Additional hardening

  • Upgrade VMware vCenter to 9.1.0.0300 (for 9.1.x lines), 9.0.2.0100 (for 9.0.x lines), or 8.0 U3k (for 8.0 lines). Broadcom states no workaround is available; patching is the required remediation. Consult the vendor advisory in References for Cloud Foundation, vSphere Foundation, and Telco product guidance.
  • Restrict network access to the vCenter management interface and Syslog server port to explicitly defined management hosts and networks using firewall rules or network segmentation. Internet-routable access to vCenter should be removed entirely.
  • Audit vCenter hosts for indicators of post-exploitation activity, including unexpected SSH authorized_keys entries, new cron jobs, unfamiliar processes, and outbound connections to external infrastructure, consistent with the reverse SSH persistence technique observed in active exploitation campaigns.
  • Apply the principle of least exposure: vCenter should not be reachable from untrusted networks under any operational configuration. Verify perimeter controls are enforced and review any cloud or hosted deployments for unintended public exposure.

Key dates

Published (NVD)
July 30, 2026
Added to CISA KEV
August 18, 2026
Remediation deadline
August 21, 2026
Last updated
August 19, 2026

References

Frequently asked questions

Does CVE-2026-59310 affect my FedRAMP authorization?

If Broadcom VMware vCenter runs inside your authorization boundary, CVE-2026-59310 is a direct concern for your FedRAMP authorization. The vulnerability appears on CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 21, 2026. An unpatched KEV within your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that deadline.

How does Knox help me handle CVE-2026-59310?

Knox does not patch Broadcom VMware vCenter on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to execute. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that work, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The patch is your responsibility; maintaining a compliant posture while you apply it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-59310 surfaces, exposure is identified through continuous monitoring rather than waiting for an assessor to flag it at a scheduled review. That earlier visibility gives your team more time to act before a finding becomes a formal issue.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-59310 isn't remediated by August 21, 2026?

If CVE-2026-59310 is not remediated by August 21, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and preserves the agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting