VULNERABILITY OVERVIEW
Also released July 29, 2026 in VMSA-2026-0006, this critical directory traversal flaw in the vCenter Syslog server allows a network-adjacent unauthenticated attacker to read or write arbitrary files, leading to arbitrary code execution on the vCenter appliance host. The vulnerability requires no privileges or user interaction. Broadcom has stated no exploitation has been observed in the wild as of advisory publication; no workaround is available and patching is the only remediation.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONS
VMware Cloud Foundation/vSphere Foundation 9.1.x (fixed in 9.1.0.0300), 9.0.x (fixed in 9.0.2.0100), 8.0 U3k; vCenter 5.x within applicable Telco Cloud productsCITATIONS
- → https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- → https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
- → https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html
- → https://cyberpress.org/critical-vmware-vcenter-flaws/