Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
What happened
Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom VMware vCenter. This flaw, tracked as CVE-2026-59310 with a CVSS score of 9.8, allows unauthenticated attackers with network access to execute arbitrary code.
Why it ranks #1
Confirmed active exploitation of a critical vulnerability in core enterprise virtualization infrastructure takes top priority over other vulnerabilities and breaches.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply the available patches for VMware vCenter immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed