CVE-2026-59310 – VMware Cloud Foundation

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A critical vCenter flaw puts the virtualization management plane at risk of complete code execution.”

CVE-2026-59310 is a Critical directory traversal vulnerability in the vCenter Syslog server affecting VMware Cloud Foundation. An unauthenticated attacker with network access to vCenter can exploit the flaw to execute arbitrary code. The CVSS score is 9.8, which is Critical severity.

VMware has released fixed versions for affected vCenter and Cloud Foundation deployments. There is no workaround, making the security update the available remediation.

Key Details

Affected Product
Vmware Vcenter Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-22
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.