Skip to finding
important · Edge — virtualization

Public exploit code turns vCenter's unauthenticated syslog file write into repeatable root command execution.

Affects

VMware vCenter Server, the virtualization-management appliance used by vSphere, VMware Cloud Foundation and related platforms.

A traversal-bearing RFC 5424 APP-NAME makes the dynamic rsyslog template write a root-owned cron entry outside its intended directory.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026