CVE-2026-59310
CRITICAL · 9.8 KEV EPSS 45.9%Claimed active exploitation and reverse-SSH deployment, but low EPSS and no KEV listing temper signal.
What: Directory traversal in VMware vCenter Syslog Server allowing unauthenticated remote code execution (CVSS 9.8 CRITICAL).
Why it matters: Social chatter reports active exploitation campaigns deploying reverse SSH tools for persistence. Multiple security news outlets covering in-the-wild attacks. VMware has patched (advisory issued 2026-07-30). However, CVE is NOT yet on CISA KEV list, and EPSS remains extremely low (0.63 percentile), suggesting limited observed exploitation despite claimed global campaign reports.
Where it's seen: Security blogs, Bluesky posts, and threat intelligence feeds claiming "active global intrusion campaign" and "scanning in the wild." Posts link to Bleeping Computer and HackerNews coverage amplifying the threat narrative.
RISK: HIGH — Network-accessible RCE with critical CVSS; unpatched vCenter instances remain vulnerable.
Description
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High