🔴 Critical  |  Source: The Hacker News


A critical directory-traversal vulnerability in VMware vCenter Server (CVE-2026-59310, CVSS 9.8) is being actively exploited in the wild, allowing unauthenticated attackers with network access to execute arbitrary code remotely. vCenter is a widely deployed management platform for VMware virtualisation infrastructure, meaning successful exploitation can grant attackers control over entire virtualised environments. Patches have been released by Broadcom and should be applied immediately given confirmed active exploitation.

Security Architect’s Take: Apply Broadcom’s patch for CVE-2026-59310 immediately and, as an interim measure, restrict network access to vCenter management interfaces via firewall rules or network segmentation — vCenter should never be exposed to untrusted networks. Audit recent vCenter access logs for anomalous activity or signs of lateral movement across your virtualised estate.

Original advisory: Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access