www.darkreading.com 8/13/2026, 9:32:11 PM · external

Experts Warn VMware vCenter Zero day Flaw Exploited Worldwide

Experts Warn VMware vCenter Zero day Flaw Exploited Worldwide
Developing story vulnerability 3 articles tracked
Broadcom patches multiple critical VMware vCenter and ESXi vulnerabilities
CyberSIXT Evidence Panel
Primary Source medium.com

A critical vulnerability in VMware vCenter, identified as CVE-2026–59310, has been under active exploitation since early August, shortly after its disclosure on July 29. With a CVSS score of 9.8, the flaw allows remote attackers to execute arbitrary code within a vulnerable instance of vCenter. The exploitation is being traced to a single threat actor impacting users across at least 47 countries, including the US and France.

Despite VMware releasing a patch, experts warn that attackers might maintain access through reverse_ssh, indicating that merely patching the vulnerability may not fully secure systems. Organizations are advised to conduct forensic investigations of potentially compromised systems, as the complex nature of virtual environments makes timely patching challenging.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline