Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Summary

Threat actors are actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, which allows for arbitrary code execution. This directory-traversal flaw, with a CVSS score of 9.8, enables attackers with network access to gain persistent remote access. Patches for this vulnerability have been released.

IFF Assessment

FOE

This vulnerability allows attackers to gain persistent remote access and execute arbitrary code, posing a significant threat to organizations relying on VMware vCenter.

Severity

9.8 Critical

Defender Context

Organizations using VMware vCenter must urgently apply the provided patches for CVE-2026-59310 to prevent attackers from exploiting this critical vulnerability. Attackers are actively leveraging this flaw, indicating a high likelihood of exploitation attempts against unpatched systems, leading to potential data breaches and system compromise.

Read Full Story →