CISA KEV Adds VMware vCenter Path Traversal Flaw (CVE-2026-59310) Amid Active Exploitation
What Happened
Broadcom has disclosed a path traversal vulnerability in VMware vCenter, tracked as CVE-2026-59310, that could allow a threat actor with network access to vCenter to execute arbitrary code. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating it is being actively exploited in the wild. No CVSS score has been published at this time, and the known-ransomware-use status is currently listed as unknown.
Why It Matters
vCenter Server is the central management plane for VMware vSphere environments, making it a high-value target: compromise can provide an attacker with control over an organization's entire virtualization infrastructure, including the ability to access, modify, or exfiltrate data across every hosted virtual machine. Path traversal vulnerabilities that lead to arbitrary code execution are especially dangerous because they can potentially be exploited without prior authentication, depending on the affected endpoint. Any organization running VMware vCenter with network-reachable management interfaces should treat this as an urgent risk given its KEV status and active exploitation.
What Defenders Should Watch For
- Identify all vCenter Server instances in your environment and confirm network exposure — particularly whether the management interface is reachable from untrusted or broader internal networks.
- Consult Broadcom's advisory for affected versions and apply vendor-supplied patches or mitigations as soon as they are available and validated.
- Restrict network access to vCenter management interfaces to a minimal, tightly controlled administrative segment.
- Review vCenter access and web server logs for anomalous request patterns consistent with path traversal attempts (e.g., unexpected directory-escape sequences in URLs or file paths).
- Monitor for unexpected process execution, new administrative accounts, or configuration changes originating from the vCenter host, which could indicate successful exploitation.
- Since CISA KEV inclusion often carries federal remediation deadlines, prioritize this vulnerability in patch management workflows even outside federal environments.
Developing Intel
This is a same-day KEV addition and details are still emerging — CVSS scoring, full technical exploitation details, and patch guidance may be updated by Broadcom and CISA in the near term. Defenders should monitor the official advisory directly for the latest information: Broadcom Security Advisory.