ZeroDayAlert

CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

Broadcom VMware vCenter Added to KEV 2026-08-18 Federal due 2026-08-21 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Broadcom VMware vCenter deployments are affected by a path traversal vulnerability that permits arbitrary code execution. The vulnerability requires network access to vCenter; the record does not specify affected version ranges, whether the vulnerability is pre-authentication or post-authentication, or which vCenter deployment models (on-premises, cloud-hosted, or management clusters) are in scope.

How to check whether this touches you

  • Inventory: Do you operate VMware vCenter in any deployment model (on-premises, hybrid, or cloud-hosted)?
  • Reachability: Confirm whether your vCenter instance is reachable from untrusted networks—via direct internet exposure, shared corporate networks, or internal subnets where threat actors may already be present.
  • Version confirmation: Query your vCenter appliances or inventory tools for the running version number. Check Broadcom's advisory for the affected range and any version-specific fingerprints; note that some distributions backport security fixes, so version alone does not prove immunity.
  • Network segmentation: Determine which systems and users can initiate connections to vCenter APIs, web consoles, and management interfaces.

What to do

  1. Immediately: Locate Broadcom's security advisory for CVE-2026-59310 and confirm the affected version range for your deployments.
  2. If you can patch now: Apply the vendor patch following Broadcom's instructions and test in a non-production environment first.
  3. If you cannot patch immediately: Restrict network access to vCenter to only authorised administrative hosts and jump servers; disable or isolate any vCenter instances that are not critical until patches are available.
  4. Log and monitor: Enable audit logging on all vCenter instances if not already active; configure alerts for path traversal patterns (unusual file access sequences or attempts to traverse parent directories) in vCenter logs.
  5. Compliance: Follow CISA BOD 26-04 timelines for your organisation's risk category; if mitigations are unavailable and you cannot patch within the required window, escalate to your security leadership for discontinuation decisions.

If you find you were exposed

Exploitation of path traversal flaws often precedes public disclosure, so retrospective hunting requires searching vCenter audit logs, hypervisor access logs, and API request logs for suspicious file-access patterns prior to the advisory date. Logs older than your retention window cannot be recovered; if you lack logs covering the period since vCenter was first deployed or last patched, document that gap and focus on forward-looking detection after remediation.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-59310 is being exploited. It cannot tell you whether VMware vCenter is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →