A global threat campaign is actively exploiting a critical vulnerability in VMware vCenter, specifically CVE-2026-59310, which was first targeted earlier this month. The exploitation of this flaw poses significant risks, as patching the vulnerability may not be sufficient to fully mitigate the threat. The vulnerability affects VMware vCenter users, who may still be at risk even after applying patches. The campaign's scope and impact are considerable, with potential consequences for organizations relying on VMware vCenter. The fact that patching may not be enough to fully address the issue underscores the need for additional mitigation measures1. This situation matters to security practitioners because it highlights the limitations of patching as a sole mitigation strategy, emphasizing the need for a more comprehensive approach to securing critical infrastructure.