VMware vCenter Flaw Actively Exploited for Remote Code Execution
A critical directory traversal vulnerability in VMware vCenter is being exploited in the wild. Organizations must patch immediately to prevent persistent remote access by attackers.
TL;DR
- CVE-2026-59310 is a critical directory traversal flaw in VMware vCenter with CVSS score 9.8.
- Exploitation allows unauthenticated remote code execution with high impact.
- Threat actors are actively exploiting the vulnerability despite patches being available.
- Organizations using VMware vCenter should apply updates immediately.
- Persistent backdoor access is possible if systems remain unpatched.
Security researchers have identified active exploitation of a critical vulnerability in VMware vCenter servers. The flaw, tracked as CVE-2026-59310, allows attackers to gain persistent remote access through directory traversal techniques.
This vulnerability poses significant risk to organizations relying on VMware's virtualization platform. With a CVSS score of 9.8, it represents a severe threat that requires immediate attention from security teams.
Vulnerability Details
- CVE-2026-59310 is a directory traversal vulnerability affecting VMware vCenter Server
- The flaw has a critical CVSS score of 9.8 due to its remote exploitation potential
- Attackers can leverage the vulnerability to execute arbitrary code on affected systems
- No authentication is required to exploit the vulnerability, making it particularly dangerous
- Successful exploitation can lead to complete system compromise and persistent access
Security Recommendations
- Immediately apply the latest security patches from VMware for vCenter Server
- Review network logs for suspicious activity indicating potential exploitation attempts
- Implement network segmentation to limit access to vCenter management interfaces
- Monitor for unauthorized changes to system configurations or file modifications
- Consider temporary network isolation of vCenter instances until patches are applied
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.