Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 3 MIN AGO
T-3M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-59310
vCenter directory-traversal vulnerability
Critical
KEV
PUBLISHED
CNA: vmware
Base score
9.8
CVSS v3.x
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
View raw JSON
CVE Program record
02
Description
CNA: vmware
vCenter directory-traversal vulnerability
03
Metadata
SCHEMA: 5.2
Published
2026-07-30 12:19Z
23 DAYS AGO
Last updated
2026-08-18 19:58Z
4 DAYS AGO
Reserved
2026-07-04
Assigning CNA
vmware
Record state
PUBLISHED
Severity
Critical (CVSS 9.8)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Base
SSVC decision
Exploitation
active
Automatable
yes
Technical Impact
total
KEV catalog
Added 2026-08-18 · remediation due 2026-08-21
Data version
5.2
Document digest
5674c8a8a3e8f9563d21776acc41af6e8a02f45e23944b749dfe52e518717e3f
04
Affected products
PAIRS: 5
Vendor
Product
Versions
Platforms
VMware
Cloud Foundation
9.1.x.x, 9.0.x.x, 5.x
—
VMware
vSphere Foundation
9.1.x.x, 9.0.x.x
—
VMware
vCenter
9.1.x.x to < 9.1.0.0300, 9.0.x.x to < 9.0.2.0100, 8.0 to < 8.0 U3k
—
VMware
Telco Cloud Infrastructure
3.0
—
VMware
Telco Cloud Platform
5.1.x, 5.0.x, 4.x, 3.0
—
05
References
REFS: 4
support.broadcom.com
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
medium.com
https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
third-party-advisory
medium.com
https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
third-party-advisory
www.cisa.gov
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
government-resource