Critical VMware vCenter Flaw Under Active Exploitation
TL;DR. Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter, leading to remote code execution. - Tracked as CVE-2026-59310, the flaw carries a CVSS score of 9.8. - Exploitation began shortly after disclosure, targeting web-accessible vCenter servers. - Attackers use a reverse shell for persistent access to compromised systems.
- A critical vulnerability (CVE-2026-59310) in VMware vCenter, leading to remote code execution, is being actively exploited.
- The directory traversal bug allows malicious actors with network access to execute arbitrary code.
- Exploitation by an advanced persistent threat (APT) actor started shortly after the vulnerability's disclosure.
- More than 360 victim IP addresses across 47 countries have been identified.
- Attackers deploy an open-source SSH reverse shell for persistent outbound control connections.
Sources
- Critical VMware vCenter Vulnerability in Attackers’ Crosshairs — securityweek.com
- bleepingcomputer.com — bleepingcomputer.com