← Back to blog

VMware vCenter Flaw Actively Exploited for Remote Code Execution

A critical directory traversal vulnerability in VMware vCenter is being exploited in the wild. Organizations must patch immediately to prevent persistent remote access by attackers.

TL;DR

  • CVE-2026-59310 is a critical directory traversal flaw in VMware vCenter with CVSS score 9.8.
  • Exploitation allows unauthenticated remote code execution with high impact.
  • Threat actors are actively exploiting the vulnerability despite patches being available.
  • Organizations using VMware vCenter should apply updates immediately.
  • Persistent backdoor access is possible if systems remain unpatched.

Security researchers have identified active exploitation of a critical vulnerability in VMware vCenter servers. The flaw, tracked as CVE-2026-59310, allows attackers to gain persistent remote access through directory traversal techniques.

This vulnerability poses significant risk to organizations relying on VMware's virtualization platform. With a CVSS score of 9.8, it represents a severe threat that requires immediate attention from security teams.

Vulnerability Details

  • CVE-2026-59310 is a directory traversal vulnerability affecting VMware vCenter Server
  • The flaw has a critical CVSS score of 9.8 due to its remote exploitation potential
  • Attackers can leverage the vulnerability to execute arbitrary code on affected systems
  • No authentication is required to exploit the vulnerability, making it particularly dangerous
  • Successful exploitation can lead to complete system compromise and persistent access

Security Recommendations

  • Immediately apply the latest security patches from VMware for vCenter Server
  • Review network logs for suspicious activity indicating potential exploitation attempts
  • Implement network segmentation to limit access to vCenter management interfaces
  • Monitor for unauthorized changes to system configurations or file modifications
  • Consider temporary network isolation of vCenter instances until patches are applied

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

VMware vCenter Flaw Actively Exploited for Remote Code Execution — Agent Breach Blog | Agent Breach