CVE-2026-59310 is an unauthenticated path traversal in the VMware vCenter Syslog server rated CVSS 9.8. Broadcom disclosed it on July 29, attackers were exploiting it by August 3, and forensics firm Quirso counted 361 victim IPs across 47 countries. There is no workaround.

Read the full story: vCenter's 9.8 Flaw Was Exploited Five Days After Disclosure →

Transcript

Broadcom disclosed this vCenter flaw on July twenty ninth. By August third, people were exploiting it. Five days. It's a path traversal in the vCenter Syslog server, rated nine point eight, and it needs no credentials at all. Just network access. There is no workaround. But here's the part that catches people out. German forensics firm Quirso found the real attack chain during incident response, and it doesn't stop at code execution. The attackers wrote a cron job for persistence, then opened an outbound channel back to their own infrastructure. Patching closes the way in. It does not delete a cron job that already exists. So two clocks are running: close the hole, and evict whoever already came through. Quirso counted three hundred sixty one victim hosts across forty seven countries. And enterprise virtualization does not patch in five days. Most of those victims weren't careless.