VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVMware Cloud Foundation
APPVmwareall versionsVMware Telco Cloud Infrastructure
APPVmware3.0VMware Telco Cloud Platform
APPVmware3.0 – 5.2VMware Vcenter Server
APPVmware8.0< 8.09.0 – 9.0.2.0100 (excl.)9.1 – 9.1.0.0300 (excl.)VMware vSphere Foundation
APPVmwareall versions
CISA KEV — detailsi
- Vendori
- Broadcom
- Producti
- VMware vCenter
- Added to KEVi
- August 18, 2026
- Remediation deadline (US Federal)i
- August 21, 2026(overdue)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Related vulnerabilities
VMware ESXi/Workstation: TOCTOU umożliwia ucieczkę z VM przez VMX process
VMware vCenter Server — heap-overflow w DCERPC umożliwia RCE
Heap overflow w VMware vCenter Server via protokół DCERPC — RCE
VMware vCenter Server — RCE przez out-of-bounds write w protokole DCERPC
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection