Summary
- CVE-2026-59310 is a critical vCenter directory-traversal flaw that can allow arbitrary code execution over the network.
- Broadcom rates the vulnerability CVSS 9.8 and lists no workaround for affected deployments.
- CISA’s Known Exploited Vulnerabilities record identifies the flaw as associated with known ransomware campaign use.
A critical vulnerability in VMware vCenter has gained an additional ransomware dimension after the US Cybersecurity and Infrastructure Security Agency identified the flaw as associated with known ransomware campaign use.
CVE-2026-59310 is a directory-traversal vulnerability in the vCenter Syslog server. Broadcom rates it critical with a maximum CVSS score of 9.8 and says an attacker with network access to vCenter may exploit it to execute arbitrary code.
No workaround is available. Broadcom’s advisory directs customers to apply the patched versions identified in its response matrix.
The vulnerability was originally disclosed on 29 July and added to CISA’s Known Exploited Vulnerabilities catalogue on 18 August after evidence of real-world exploitation. CISA’s catalogue record also marks known ransomware campaign use.
That association matters because vCenter occupies a highly privileged place in virtualised infrastructure. It provides central management for environments that may support large numbers of business services, giving administrators visibility and control across hosts and virtual machines.
Infrastructure with that level of control is attractive during extortion attacks. Ransomware operators increasingly target technologies that can broaden access, interfere with recovery, disable security controls, or allow multiple systems to be affected from one privileged position.
Virtualisation platforms have repeatedly become part of that strategy because many workloads can depend on a relatively small number of management components.
The network-access requirement means internet exposure is not the only relevant scenario. A compromised internal host may provide a route to vCenter if management networks are broadly reachable, making segmentation, privileged access controls, and internal monitoring important alongside patching.
The flaw also demonstrates why vulnerability priority cannot remain static. A CVSS score of 9.8 already indicates serious technical impact, but evidence of exploitation and association with ransomware campaigns changes the operational context.
Remediation systems that rank vulnerabilities only by base severity can miss that shift if known exploitation, asset criticality, and threat activity are not incorporated into the decision.
Cyber Insider previously included the vCenter vulnerability in coverage of actively exploited enterprise vulnerabilities. The ransomware association is the substantive development since that article.
Maintenance may still be difficult in large virtualisation estates. Updating central management infrastructure can require compatibility testing, change windows, and coordination across teams responsible for workloads that depend on the platform.
Those constraints do not change the exposure. Broadcom has provided patched versions, CISA has confirmed exploitation, and no workaround is available. The remaining question for organisations running affected versions is whether the management infrastructure has been identified and updated before attackers reach it.





