VMware vCenter RCE CVE-2026-59310: CVSS 9.8 [2026]

VMware vCenter RCE CVE-2026-59310: CVSS 9.8 [2026]

By shattered.io
Publication Date: 2026-09-15 14:02:00

The Cybersecurity and Infrastructure Security Agency confirmed on September 15, 2026, that ransomware gangs have joined attackers already exploiting a critical remote code execution flaw in VMware vCenter Server, according to a BleepingComputer report by Sergiu Gatlan. The bug, tracked as CVE-2026-59310, carries a CVSS score of 9.8 out of 10 and sits in the vCenter Syslog server, where an unauthenticated attacker with network access can run arbitrary code. Broadcom, which owns VMware, shipped a fix on July 29. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 18 and gave federal agencies just three days to patch.