CVE-2026-59310
Serial number: AV26-763 Date: July 30, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-25557999 Prior to ESXi80U3i-25205845 Prior to ESXi80U3k-25595708 Fusion Prior to 26H1 Telco Cloud Infrastructure 3.0 Telco Cloud Platform 4.x 5.0.x 5.1.x Workstation Prior to 26H1 vCenter Prior to 8.0 U3k Prior to 9.0.2.0100 Prior to 9.1.0.0300 vSphere Foundation 9.0.x.x 9.1.x.x The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) Security Advisories - VMware Cloud Foundation
CSIRTS triage
- What
- VMware products are affected by multiple vulnerabilities.
- Who is affected
- Users and administrators of various VMware products listed in the advisory.
- Urgency
- Remediation is necessary due to multiple vulnerabilities, though severity is unknown.
- Action
- Review the provided web links and apply necessary updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-59310
Get an email if CVE-2026-59310 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk1.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
Advisory coverage (5)
- high[NEW] [high] VMware Products: Multiple vulnerabilitiescert-bund · 2026-07-31
- unknownVMware security advisory (AV26-763)cccs · 2026-07-30
- criticalCVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious …nvd · 2026-07-30
- unknownMultiple Vulnerabilities in VMware Products (July 30, 2026)cert-fr-avis · 2026-07-30
- unknownNCSC-2026-0269 [1.01] [M/H] Vulnerabilities fixed in VMware productsncsc-nl · 2026-07-29
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-59310)