CVE-2026-59310 · High · CISA KEV

VMware vCenter Path Traversal: Remote Code Execution Risk

Threat Engine Auto-Feed · data current as of 2026-08-19

A path traversal vulnerability in Broadcom VMware vCenter, CVE-2026-59310, allows network-accessible threat actors to execute arbitrary code. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA KEV, indicating a high exploitation pressure.

  • CVSS:
  • EPSS percentile: 0.63931
  • Exploitation pressure: 63/100 (High)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 64th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

Path traversal occurs when an application incorrectly handles user-supplied input that references file paths. This allows an attacker to access files and directories outside of the intended scope, potentially leading to unauthorized information disclosure or, in this case, arbitrary code execution.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations utilizing VMware vCenter for virtualization management, particularly those with network exposure to vCenter instances.
  • Financial services and Technology sectors, given documented adversary targeting.

Misconfigurations that escalate it

  • Any network configuration that grants untrusted or overly permissive network access to vCenter instances.
  • Lack of robust network segmentation between vCenter and less trusted network zones.

High-impact scenarios

  • An attacker gaining remote code execution on the vCenter server, leading to full control over the virtualized environment.
  • Compromise of critical infrastructure and sensitive data hosted within the virtualized environment.
  • Potential for lateral movement into connected systems and broader network compromise.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor network traffic for unusual connections or data exfiltration attempts originating from vCenter instances.
  • Review vCenter logs for suspicious activity, unauthorized file access, or unexpected process execution.
  • Implement intrusion detection/prevention systems (IDS/IPS) to identify known attack patterns targeting path traversal vulnerabilities.

Contain

  • Isolate affected vCenter instances from the network to prevent further compromise.
  • Restrict network access to vCenter to only essential administrative hosts and services.
  • Temporarily disable non-critical services on vCenter that might be leveraged for exploitation.

Patch

  • Apply the latest security patches and updates from Broadcom for VMware vCenter immediately.

Frontier verdict — High

This critical vulnerability in VMware vCenter, actively exploited in the wild and enabling remote code execution, demands immediate patching and heightened defensive measures.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.