CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability

Summary

A path traversal vulnerability in Broadcom VMware vCenter could allow an unauthenticated attacker with network access to execute arbitrary code. CISA advises applying vendor-provided mitigations and adhering to its BOD 26-04 guidance for prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution, posing a significant risk to systems and data.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 21, 2026. Known ransomware use: Unknown.

Defender Context

This critical path traversal vulnerability in VMware vCenter requires immediate attention from defenders. Organizations must prioritize applying the relevant patches or mitigations provided by Broadcom to prevent potential remote code execution and subsequent compromise, especially given the potential for ransomware exploitation.

Read Full Story →