Attackers are leveraging a critical directory-traversal vulnerability, designated as CVE-2026-59310, to gain persistent remote access to VMware vCenter servers. This flaw, which carries a CVSS score of 9.8, can be exploited by malicious actors with network access to execute arbitrary code. Patches for the vulnerability were recently released, but threat actors have already begun to actively exploit the flaw, according to research from QUIRSO1. The vulnerability allows attackers to traverse directories and execute code, potentially leading to a complete takeover of the vCenter server. This exploit enables attackers to maintain remote access, even after the system has been restarted. The exploitation of this vulnerability expands the active attack surface, making it crucial for organizations to prioritize patching based on their exposure and evidence of exploitation. This vulnerability poses a significant risk to organizations relying on VMware vCenter, and prompt action is necessary to prevent potential breaches.