A critical vulnerability in VMware's vCenter, identified as CVE-2026-59310, was publicly disclosed on July 29, 2026, and exploited within just five days. The flaw, rated CVSS 9.8, allows unauthenticated attackers to execute arbitrary code on compromised systems. Following the disclosure, a security firm observed attacks targeting 361 victim IP addresses across 47 countries, indicating the rapid exploitation of the vulnerability.
The attacker utilized an open-source reverse shell to maintain access, prompting experts to emphasize the need for immediate patching and awareness of potential hackers who may have already exploited the flaw prior to applying fixes.