Attackers are leveraging a critical directory-traversal vulnerability, designated as CVE-2026-59310, to gain persistent remote access to VMware vCenter servers. This flaw, which carries a CVSS score of 9.8, can be exploited by malicious actors with network access to execute arbitrary code. Patches for the vulnerability were recently released, but threat actors have already begun to actively exploit the flaw, according to research from QUIRSO1. The vulnerability allows attackers to traverse directories and execute code, potentially leading to a complete takeover of the vCenter server. This exploit enables attackers to maintain remote access, even after the system has been restarted. The exploitation of this vulnerability expands the active attack surface, making it crucial for organizations to prioritize patching based on their exposure and evidence of exploitation. This vulnerability poses a significant risk to organizations relying on VMware vCenter, and prompt action is necessary to prevent potential breaches.
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
⚠️ Critical Alert
Why This Matters
CVE-2026-59310 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- The Hacker News. (2026, August 12). Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access. *The Hacker News*. https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
Original Source
The Hacker News
Read original →