www.infosecurity-magazine.com 8/13/2026, 2:31:10 PM · external

VMware vCenter CVE-2026-59310 flaw exploited worldwide within days

VMware vCenter CVE-2026-59310 flaw exploited worldwide within days
Developing story vulnerability 4 articles tracked
Broadcom patches multiple critical VMware vCenter and ESXi vulnerabilities
CyberSIXT Evidence Panel
Primary Source support.broadcom.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in VMware's vCenter, identified as CVE-2026-59310, was publicly disclosed on July 29, 2026, and exploited within just five days. The flaw, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary code on compromised systems. Following the disclosure, a security firm observed attacks targeting 361 victim IP addresses across 47 countries, indicating the rapid exploitation of the vulnerability.

The attacker utilized an open-source reverse shell to maintain access, prompting experts to emphasize the need for immediate patching and awareness of potential hackers who may have already exploited the flaw prior to applying fixes.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline