vCenter 7.0 and CVE-2026-59310: Actively Exploited, Fixed Only for Extended-Support Contracts — What Broadcom's Advisory Actually Says
On August 18, 2026 CISA added CVE-2026-59310 — a CVSS 9.8 path-traversal flaw in the VMware vCenter Syslog server that allows remote code execution — to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of August 21. Broadcom's advisory VMSA-2026-0006 ships fixes for vCenter 8.0 (U3k and U2f) and for VMware Cloud Foundation / vSphere Foundation 9.0 (9.0.2.0100) and 9.1 (9.1.0.0300). For vCenter 7.0, which ended general support on October 2, 2025, the response matrix says one thing: “Contact Broadcom Support if you have extended support contract.” No public build. No workaround.
That sentence is the whole story for a large part of the installed base. vCenter 7.0 is still common — it was the line that most perpetual-licence estates settled on before Broadcom ended perpetual sales — and the people most likely to be on it are the people least likely to hold an extended-support contract. This page says precisely who can get the fix, who cannot, why Broadcom's zero-day patch program does not change that, and what to do this week.
Key Dates at a Glance
- vCenter 7.0: released 2020-04-02; end of general support 2025-10-02
- vCenter 8.0: end of general support 2027-10-11
- VMware Cloud Foundation 9.0 (vCenter 9.0): end of general support 2027-09-17
- VMware Cloud Foundation 9.1 (vCenter 9.1): released 2026-05-12; end of general support 2028-08-12
- VMSA-2026-0006: published 2026-07-29; revision .2 published 2026-08-19
- CVE-2026-59310: added to CISA KEV 2026-08-18; federal remediation due 2026-08-21
What Broadcom's Advisory Says, Line by Line
VMSA-2026-0006 (first published July 29, 2026, revised to .2 on August 19) covers five CVEs across vCenter and ESX. The two vCenter flaws are both rated 9.8: CVE-2026-59309, an authentication bypass in the VMware Directory Service, and CVE-2026-59310, the Syslog-server path traversal that CISA has now confirmed is being exploited. The vCenter response matrix, as published:
| Product | Version | Fixed version | Workarounds |
|---|---|---|---|
| VMware Cloud Foundation / vSphere Foundation | 9.1.x | 9.1.0.0300 | None |
| VMware Cloud Foundation / vSphere Foundation | 9.0.x | 9.0.2.0100 | None |
| VMware vCenter | 8.0 | 8.0 U3k | None |
| VMware vCenter | 8.0 | 8.0 U2f | None |
| VMware vCenter | 7.0 | “Contact Broadcom Support if you have extended support contract.” | None |
| VMware Cloud Foundation | 5.x | Async patch to 8.0 U3k | None |
Read the 7.0 row carefully. It does not say “no patch planned” (the wording Broadcom used for ESXi 7.0 and CVE-2024-37085). It says a fix exists for customers who hold an extended support contract. That is a meaningful difference, and it is why this entry is not in our Exploited & Unpatchable feed — see below.
Who Can Get the 7.0 Fix — and Who Cannot
Three populations run vCenter 7.0 today, and the advisory treats them very differently.
- Extended-support contract holders. Broadcom's matrix points them to Support; the fix is obtained through a case, not a public download. If you are unsure whether your contract qualifies as “extended support” rather than standard SnS, that is the first question to ask Broadcom.
- Active SnS, but no extended-support contract. vCenter 7.0 left general support on October 2, 2025. Standard support and subscription does not entitle a 7.0 instance to a post-general-support fix; the sanctioned path is the upgrade to 8.0 U3k.
- Perpetual licence, SnS expired. This is the group the perpetual-licence transition created, and it is the group with nothing. Broadcom's zero-day security patch program (KB 314603, announced April 15, 2024) gives perpetual customers with expired contracts access to patches for CVSS 9.0+ flaws — but only for vSphere 8.x, vCenter Server 8.0 and ESXi 8.0. A 7.0 instance is outside general support and outside the zero-day program. The software keeps running (SnS expiry does not revoke the licence); it simply never receives this fix.
The background to all of this — what ended when Broadcom stopped selling perpetual licences, what a lapsed SnS does and does not take away — is in VMware perpetual licence end of availability.
Why This Is Not in Our Exploited & Unpatchable Feed
Our Exploited & Unpatchable feed lists versions that are on CISA's KEV catalog, past end of life, and for which no fix exists by any route. A vendor fix available under a paid contract is a route — it is the same reason Exchange and SharePoint versions covered by Microsoft ESU are excluded, and the same rule that keeps ESXi 7.0 and CVE-2024-37085 in (Broadcom's wording there: “No Patch Planned”). vCenter 7.0 and CVE-2026-59310 is therefore “unpatched unless you pay”, not “unpatchable”. We apply the rule even when it makes the story less dramatic, because the feed is only useful if every entry survives a hostile reading. If Broadcom ever states that no 7.0 fix will be issued, the entry goes in.
vCenter EOL Risk Scores
We publish an EOL Risk Score (0–100) for every tracked version, combining how long past — or how close to — end of life it is, the attack surface of the software class, whether CISA lists the product in its KEV catalog, and whether commercial extended support exists. vCenter is management-plane infrastructure with repeated KEV entries; that baseline is high before any lifecycle factor applies.
| Version | EOL Risk Score | What drives it |
|---|---|---|
| vCenter 7.0 | 60 | End of general support October 2, 2025; KEV exposure; extended support available (by contract). |
| vCenter 8.0 | 30 | Supported to October 11, 2027; patched in U3k/U2f. |
| vCenter 9.0 | 30 | Supported to September 17, 2027; patched in 9.0.2.0100. |
Scores update automatically at every build; every line is on the vCenter product page.
What to Do This Week
- 8.0 and 9.x: apply 8.0 U3k / U2f, 9.0.2.0100 or 9.1.0.0300. CISA's deadline for federal agencies is August 21, 2026; treat it as yours.
- 7.0 with extended support: open the case with Broadcom Support today and obtain the 7.0 fix; do not wait for a public build that is not coming.
- 7.0 without extended support: assume exposure now — restrict network access to the vCenter management interface to the narrowest possible set of hosts, review for unauthorised SSH keys, accounts and scheduled tasks, and follow the indicators in Broadcom's advisory FAQ. Then choose the exit: upgrade to vCenter 8.0 U3k (7.0 → 8.0 is a supported upgrade path and 8.0 is supported to October 11, 2027), or buy extended support and get the patch. Both cost money; running exploited, unpatched management-plane software costs more. How extended support works.
- Everyone: check ESXi too — the same advisory carries CVE-2026-47876 (VMXNET3, CVSS 9.3) for ESX hosts.
Frequently Asked Questions
Is vCenter 7.0 patched for CVE-2026-59310?
Not publicly. Broadcom's advisory VMSA-2026-0006 lists fixed builds for vCenter 8.0 (U3k and U2f) and for VMware Cloud Foundation / vSphere Foundation 9.0 (9.0.2.0100) and 9.1 (9.1.0.0300). For vCenter 7.0 the response matrix says only: 'Contact Broadcom Support if you have extended support contract.' There is no fixed build listed and no workaround. vCenter 7.0 reached end of general support on October 2, 2025.
What is CVE-2026-59310?
A path-traversal flaw in the vCenter Syslog server that lets an attacker with network access to vCenter execute arbitrary code, rated CVSS 9.8 by Broadcom. It is one of five CVEs in VMSA-2026-0006 (first published July 29, 2026; revised August 19, 2026). CISA added it to the Known Exploited Vulnerabilities catalog on August 18, 2026 with a remediation due date of August 21, 2026, which means exploitation in the wild is confirmed.
I have a perpetual vCenter licence and my support contract has expired — can I get the fix?
Not for 7.0. Broadcom's zero-day security patch program for perpetual customers with expired support contracts covers vSphere 8.x only (vCenter Server 8.0 and ESXi 8.0, for CVSS 9.0 and above). A 7.0 instance with lapsed SnS is outside both routes: not in general support, and not covered by the 8.x zero-day program. The options are an upgrade to 8.0 U3k or later, or buying an extended support contract.
Which vCenter versions are supported right now?
vCenter / VMware Cloud Foundation 9.1 (released May 12, 2026, supported to August 12, 2028), 9.0 (to September 17, 2027) and vCenter 8.0 (to October 11, 2027). vCenter 7.0 ended general support on October 2, 2025. All four lines are on our vCenter product page with live status.
Why isn't this in your Exploited & Unpatchable feed?
Because it is patchable — for a price. Our feed lists only versions for which no fix exists by any route; a vendor fix available under a paid extended-support contract is a route, the same reason we exclude Exchange and SharePoint versions covered by Microsoft ESU. We apply that rule even when it makes a story less dramatic. vCenter 7.0 is therefore 'unpatched unless you pay', not 'unpatchable', and this article says exactly that.
What should I do this week if I run vCenter 7.0?
Treat it as compromised-until-proven-otherwise: restrict network access to the vCenter management interface to the narrowest set of hosts, review for unauthorised SSH keys, accounts and scheduled tasks, and check Broadcom's advisory FAQ for indicators. Then pick one of the two sanctioned exits before the next advisory: upgrade to vCenter 8.0 U3k (vCenter 7.0 → 8.0 is a supported upgrade path) or buy extended support and obtain the 7.0 patch from Broadcom Support.
Related Resources
- vCenter product page — live status, dates and risk scores for every line
- VMware perpetual licence end of availability — what a lapsed SnS does and does not take away
- VMware ESXi end of life · ESXi 7.0 and CVE-2024-37085 — the “No Patch Planned” case
- Exploited & Unpatchable — the KEV × end-of-life feed and its rules
- EOL Watch · EOL Checker · EOL Risk Score methodology