A critical flaw in VMware vCenter Server is being actively exploited across hundreds of organisations worldwide, with attackers gaining persistent remote access to compromised systems.
- What it is: CVE-2026-59310 is a directory-traversal vulnerability in vCenter Server with a maximum severity score of 9.8 out of 10, allowing an attacker with network access to run arbitrary code with no authentication required.
- Who is affected: Any business running VMware vCenter Server that has not applied the patch released in late July. Compromises have been confirmed at more than 360 organisations across 47 countries.
- The risk: Once inside, attackers install a hidden remote access tool that lets them return to the system later, even after the original entry point is closed.
- What to do: Apply Broadcom's patch immediately. There is no workaround, so unpatched systems remain exposed until updated.
We recommend confirming with your IT provider whether your virtual infrastructure runs vCenter Server and, if so, that this patch has already been applied.
Source: BleepingComputer