Skip to content
VMwareCVE-2026-59310

VMware Cloud Foundation: path traversal

Critical9.8CVE-2026-59310 · Published Jul 30, 2026 · updated Aug 19, 2026

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

VMware advisory

Affected versions

PackageAffectedFixed in
Cloud Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
<= 5.xNo fix yet
Telco Cloud Infrastructure
Product
<= 3.0No fix yet
Telco Cloud Platform
Product
<= 5.1.xNo fix yet
<= 5.0.xNo fix yet
<= 4.xNo fix yet
<= 3.0No fix yet
vCenter
Product
>= 9.1.x.x, < 9.1.0.03009.1.0.0300
>= 9.0.x.x, < 9.0.2.01009.0.2.0100
>= 8.0, < 8.0 U3k8.0 U3k
vSphere Foundation
Product
<= 9.1.x.xNo fix yet
<= 9.0.x.xNo fix yet
Details and references

More VMware advisories

All VMware
Advisory
VMware ESX contains an insufficient logging vulnerability
Low2.7Jul 30
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Cloud Foundation: out-of-bounds read
High7.6Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30
VMware Spring Tools for Eclipse: cleartext storage
Medium4.4Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.