CVE-2026-59310 – VMware Cloud Foundation
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A critical vCenter flaw puts the virtualization management plane at risk of complete code execution.”
CVE-2026-59310 is a Critical directory traversal vulnerability in the vCenter Syslog server affecting VMware Cloud Foundation. An unauthenticated attacker with network access to vCenter can exploit the flaw to execute arbitrary code. The CVSS score is 9.8, which is Critical severity.
VMware has released fixed versions for affected vCenter and Cloud Foundation deployments. There is no workaround, making the security update the available remediation.
Key Details
- Affected Product
- Vmware Vcenter Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-22
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.