Broadcom VMware vCenter Path Traversal Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- vmware vcenter (other)
- Patched version
- Not yet available
An early warning has been issued for a high-severity path traversal vulnerability in Broadcom VMware vCenter. This vulnerability could allow a threat actor with network access to execute arbitrary code.
What happened
An early warning has been issued for a high-severity path traversal vulnerability in Broadcom VMware vCenter. This vulnerability, tracked as CVE-2026-59310, could allow a threat actor with network access to execute arbitrary code. The exploit is reportedly being used in the wild. No authoritative version range has been published yet, so all users of VMware vCenter should assess their exposure.
The vulnerability was first flagged on 2026-08-18T00:00:00+00:00. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities Catalog. Users are advised to upgrade to the latest version of VMware vCenter and restrict network access to mitigate the risk.
What to do about it
- Upgrade VMware vCenter to the latest version.
- Restrict network access to VMware vCenter.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
- Consult the CISA Known Exploited Vulnerabilities Catalog for the latest information.
- Implement additional security measures to protect against path traversal attacks.
How 0Day would have caught this
vmware vcenter is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Broadcom VMware vCenter, you should assess your exposure to this vulnerability. No authoritative version range has been published yet.
What should I do right now?
Upgrade VMware vCenter to the latest version and restrict network access to the system. Monitor the primary sources for updates on the vulnerability and any official fixes.
Has this been exploited in the wild?
Yes, the exploit is reportedly being used in the wild.