important · Edge — virtualization
Public exploit code turns vCenter's unauthenticated syslog file write into repeatable root command execution.
Affects
VMware vCenter Server, the virtualization-management appliance used by vSphere, VMware Cloud Foundation and related platforms.
A traversal-bearing RFC 5424 APP-NAME makes the dynamic rsyslog template write a root-owned cron entry outside its intended directory.
Detail and 5 sources
The operational change is public code documenting a tested root shell on vCenter 9.0.2.0.
Sources
ResearchVulnCheck Exploit Database (XDB) | Community | VulnCheckCode / PoCGitHub - ChinaRan0/CVE-2026-59310-POC: CVE-2026-59310-POC 仅用于自测,请勿用于攻击 · GitHubCode / PoCadvisories/2026/ATREDIS-2026-0008.md at master · atredispartners/advisories · GitHubVendorSupport Content Notification - Support Portal - Broadcom support portalSecondaryPublic vCenter syslog exploit reaches unauthenticated root execution