CVE-2026-59310 exploited is now the relevant operating state for VMware vCenter administrators, not merely a theoretical critical-vulnerability warning. Broadcom confirms that CVE-2026-59310 is a critical directory-traversal flaw in the vCenter Syslog server that can allow a malicious actor with network access to execute arbitrary code. Broadcom assigns the vulnerability a CVSS score of 9.8, provides fixed releases and says there is no workaround.
CISA exploitation evidence materially changes the response priority. The vulnerability was added to the Known Exploited Vulnerabilities catalog on August 18, 2026, confirming exploitation in the wild. Current CISA-linked data and reporting also indicate known ransomware use, but administrator decisions should keep that campaign-level evidence separate from the vendor-confirmed vulnerability and patch facts.
Do not patch from the CVE number alone. Confirm the installed vCenter release and build before choosing the remediation path.
Broadcom lists fixed paths for supported vCenter 9.1, 9.0 and 8.0 branches. vCenter 7.0 customers covered by extended support are directed to Broadcom Support.
Broadcom states that there is no workaround for CVE-2026-59310. Remediation therefore requires moving to the applicable fixed release.
Installing the fix closes the known vulnerable condition going forward, but it does not by itself establish that a previously exposed vCenter was never compromised.
Monitor Broadcom and CISA for revised fixed versions, indicators of compromise, ransomware attribution or additional forensic guidance.
Which VMware vCenter versions fix CVE-2026-59310?
Broadcom’s current response matrix lists the following remediation paths reviewed by TPS:
| vCenter branch | Fixed release or action |
|---|---|
| 9.1 | 9.1.0.0300 |
| 9.0 | 9.0.2.0100 |
| 8.0 | 8.0 U3k or the applicable 8.0 U2f path listed by Broadcom |
| 7.0 | Extended-support customers should contact Broadcom Support |
Administrators should use Broadcom’s current advisory as the controlling source before installation because branch availability and support guidance can change.

What does CVE-2026-59310 allow?
Broadcom describes CVE-2026-59310 as a directory-traversal vulnerability in the VMware vCenter Syslog server. A malicious actor with network access may exploit the flaw to execute arbitrary code.
The vulnerability carries a CVSS score of 9.8. Because vCenter is a central management layer for VMware infrastructure, successful arbitrary-code execution on the management plane can create broader operational and security consequences than a flaw limited to a single workload.
Is CVE-2026-59310 actively exploited?
Yes. CISA exploitation metadata records the vulnerability as actively exploited and shows its addition to the Known Exploited Vulnerabilities catalog on August 18, 2026.
That distinction matters. A critical CVSS score describes technical severity; KEV inclusion establishes that exploitation is occurring in the real world. Administrators should therefore treat the flaw as an active remediation issue rather than prioritizing it solely from severity scoring.
Is ransomware using CVE-2026-59310?
Current CISA-linked KEV data and security reporting indicate known ransomware campaign use. TPS treats this as a separate evidence layer from Broadcom’s vulnerability advisory: Broadcom confirms the flaw and remediation path, while the ransomware-use state comes from CISA-linked exploitation data and subsequent reporting.
That evidence does not establish that every successful exploitation attempt deploys ransomware, that every compromised vCenter belongs to one campaign or that one named threat actor is responsible for all observed activity.
Is there a workaround for CVE-2026-59310?
No. Broadcom states that there is no workaround. Administrators should move affected systems to the applicable fixed release rather than treating network restrictions or other compensating controls as a substitute for remediation.
Network segmentation and access restrictions may still reduce exposure as general defensive controls, but TPS does not present them as vendor-recognized fixes for this vulnerability.
Does patching prove the vCenter server was never compromised?
No. A successful upgrade establishes that the known vulnerability has been remediated under the current Broadcom guidance. It does not provide retrospective proof that exploitation did not occur before the system was patched.
That is especially important because the vulnerability is now associated with confirmed exploitation. Administrators with previously exposed systems should keep patch completion and compromise assessment as two separate questions.
What about VMware vCenter 7.0?
Broadcom’s advisory does not provide the same public fixed-release path for vCenter 7.0 as it does for newer supported branches. Customers operating vCenter 7.0 under extended support are directed to contact Broadcom Support for the applicable remediation path.
TPS therefore does not infer or publish an unofficial vCenter 7.0 patch number.
How is CVE-2026-59310 different from CVE-2026-59309?
CVE-2026-59310 should not be merged with other vulnerabilities addressed in the same Broadcom security cycle. The reader task here is specifically the vCenter Syslog directory-traversal issue, its active exploitation state and its remediation path. Administrators should review the full Broadcom advisory for other vulnerabilities that may apply to their environment.
What administrators should monitor next
The current article should be revisited if Broadcom changes its fixed-release matrix, CISA updates the KEV record, new indicators of compromise become available, ransomware attribution becomes more definitive or Broadcom/CISA publishes additional compromise-assessment or recovery guidance.
Verification note
ThePulseSignal reviewed Broadcom’s VMware security advisory for the vulnerability mechanics, CVSS score, no-workaround state and fixed-release matrix, then reconciled that vendor evidence with CISA KEV-linked exploitation data and current security reporting about ransomware use.
Limitations and unresolved facts
Public evidence reviewed by TPS does not establish a complete victim count, exhaustive indicators of compromise, one definitive threat actor responsible for all exploitation or a complete campaign geography. Ransomware use should remain attributed to CISA-linked data and current reporting rather than described as a Broadcom-confirmed campaign fact.