LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog on Aug 18, 2026, with a federal patch deadline of Aug 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

CVE-2026-59310 is a path traversal weakness in Broadcom VMware vCenter. In plain terms, flawed handling of file or path input can let a threat actor who already has network reach to the vCenter management interface influence which paths the service touches, and under the conditions described by CISA that can lead to arbitrary code execution on the system hosting vCenter.

vCenter is the control plane for many VMware environments. Compromise there can affect inventory, configuration, and often the broader virtualization stack, so teams should treat this as a high-priority management-plane issue and confirm exact scope, fixed builds, and deployment notes against the vendor advisory.

How it works

This issue is classified as CWE-22 (path traversal). Products in this class fail to fully normalize or constrain user-influenced path strings, so sequences that escape an intended directory can reach files or resources outside the allowed area.

According to the CISA summary, an attacker with network access to vCenter may abuse the traversal condition in a way that results in arbitrary code execution. Public detail beyond that class-level description is limited here; do not assume a specific endpoint, authentication requirement, or payload format. Confirm attack preconditions, affected components, and any proof-of-concept status only from Broadcom’s advisory and your own lab validation. Path traversal leading to code execution typically involves writing or overwriting content the service later loads, or reaching sensitive configuration or executable locations—again, treat those as general patterns for the weakness class until the vendor states the precise mechanism.

Am I affected? How to find it in your systems

VMware vCenter Server commonly runs as a dedicated appliance or installed server that administrators and automation use to manage ESXi hosts and clusters. It may be reachable on internal management networks, jump hosts, or—if misexposed—broader enterprise or internet-facing segments.

How to remediate

Patch first. Apply the Broadcom-supplied update or remediation package that addresses CVE-2026-59310 exactly as named in the vendor advisory, following their install order, reboot, and cluster/HA considerations for vCenter.

If you can't patch immediately

Reduce exposure until the vendor fix is installed.

If your data may have been exposed

Actively exploited management-plane flaws can lead to full environment compromise, credential theft, and secondary ransomware or data theft—even when ransomware use is not documented for this specific CVE. If you suspect exploitation, isolate affected systems per your IR plan, preserve volatile evidence, rotate credentials and certificates that vCenter or admins could access, and engage forensics consistent with your obligations and CISA triage guidance where applicable.

As a routine check for personal or work email addresses that may appear in unrelated historical breaches, you can run a free exposure scan of your email against known breach datasets and then enforce password changes and MFA where reuse is possible.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBroadcom · VMware vCenter
WeaknessCWE-22
Added to CISA KEVAug 18, 2026
Federal patch deadlineAug 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities