Interestana
Home/News/Attackers Exploit VMware vCenter Vulnerability for Remote Access
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Exploit VMware vCenter Vulnerability for Remote Access

Attackers Exploit VMware vCenter Vulnerability for Remote Access

Threat actors have commenced active exploitation of a critical security vulnerability within Broadcom VMware vCenter, a widely used server management platform, according to recent findings from cybersecurity research firm QUIRSO. The vulnerability, identified as CVE-2026-59310, carries a high severity CVSS score of 9.8, indicating a significant risk. This flaw is a directory-traversal vulnerability within the VMware vCenter server, which, if exploited by a malicious actor possessing network access, allows for the execution of arbitrary code on the affected system. Patches addressing this specific vulnerability were made available by VMware, but the active exploitation suggests that many organizations have not yet applied these critical security updates.

QUIRSO's analysis indicates that attackers are leveraging this vulnerability to establish a persistent presence within compromised networks. Persistent remote access is a highly sought-after capability for threat actors, as it allows them to maintain control over a victim's systems over extended periods, facilitating further malicious activities such as data exfiltration, lateral movement to other systems, or the deployment of ransomware. The exploitation of CVE-2026-59310 enables attackers to bypass security controls and gain unauthorized administrative privileges, making it a potent tool for cybercrime. The nature of directory-traversal vulnerabilities often involves manipulating file paths to access or modify files outside of the intended directory, which can lead to code execution when combined with other system weaknesses or misconfigurations.

VMware vCenter Server is a centralized management platform for VMware's vSphere virtualization environment. It is commonly deployed in enterprise data centers to manage virtual machines, hosts, and storage. Its critical role in managing IT infrastructure makes it a prime target for attackers seeking to disrupt operations or gain access to sensitive data. The active exploitation of such a critical flaw underscores the ongoing challenges organizations face in maintaining robust cybersecurity postures, particularly in rapidly evolving threat landscapes. The speed at which vulnerabilities are being weaponized after patches are released highlights the importance of prompt patch management and vulnerability remediation strategies. Organizations that rely on VMware vCenter are strongly advised to prioritize the immediate application of the security patches released by Broadcom to mitigate the risk of compromise. Failure to do so leaves them exposed to sophisticated attacks that can have severe operational and financial consequences.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next