None
EN
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
['The Hacker News', 'Ravie Lakshmanan', 'Aug']
The Hacker News
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code.
It's worth pointing out that VMware appliances have been a lucrative target for Chinese threat actors like UNC5174, who have weaponized security flaws impacting VMware Tools and VMware vCenter in various espionage campaigns.
"The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity," QUIRSO noted.
The disclosure comes as Defused Cyber said it's observing a spike in scanning against VMware vCenter that is indicative of potential exploitation efforts targeting CVE-2026-59309 (CVSS score: 9.8).