A critical VMware vCenter vulnerability is now being actively exploited in real-world attacks. CVE-2026-59310, rated 9.8 out of 10, can allow an attacker with network access to vCenter to execute arbitrary code on the server.
- CVE-2026-59310 affects VMware vCenter Server.
- The vulnerability carries a CVSS score of 9.8.
- Active exploitation has been observed in the wild.
- The flaw can lead to arbitrary code execution.
- Broadcom says there is no workaround — patching is required.
Critical vCenter Flaw Is Under Active Attack
VMware administrators have another reason to check their vCenter patch levels immediately. CVE-2026-59310 is a critical directory traversal vulnerability affecting the Syslog server in VMware vCenter.
According to Broadcom, an attacker with network access to vCenter may exploit the vulnerability to execute arbitrary code. The flaw does not require an administrator to interact with a malicious file or link.
The issue has moved beyond a theoretical risk. Active exploitation has been observed against internet-accessible VMware infrastructure.
If your organization operates VMware vCenter, verify the installed version and patch status. Broadcom lists no workaround for CVE-2026-59310.
Hundreds of Systems Linked to the Campaign
Security researchers investigating the attacks reported compromised systems communicating with attacker-controlled infrastructure shortly after the vulnerability became public.
Researchers identified 361 victim IP addresses across 47 countries, although a single IP address does not necessarily represent a single organization.
Attackers have also been observed deploying reverse SSH tooling to maintain persistent remote access to compromised environments.
Why vCenter Is Such a Valuable Target
vCenter occupies a particularly sensitive position inside VMware infrastructure. It provides centralized management for ESXi hosts and virtual machines, making a compromised vCenter server potentially much more valuable than an individual VM.
An attacker who gains privileged access to the virtualization management layer may be able to move deeper into the infrastructure, access credentials or target ESXi hosts and their virtual machines.
Which vCenter Versions Are Fixed?
Broadcom lists patched releases including:
- vCenter 9.1: 9.1.0.0300
- vCenter 9.0: 9.0.2.0100
- vCenter 8.0: 8.0 U3k
- vCenter 8.0: 8.0 U2f for the applicable branch
Because there is no workaround, administrators running affected versions should apply the appropriate Broadcom update.
What VMware Administrators Should Do
The first priority is to determine whether vulnerable vCenter instances are still running and whether their management interfaces are unnecessarily reachable from untrusted networks.
Administrators should patch affected systems and review them for indicators of compromise. Updating a vulnerable server closes the security hole, but it does not automatically remove an attacker who may already have established persistence.
CVE-2026-59310 has become an active threat to VMware infrastructure. With a CVSS score of 9.8, observed exploitation and no available workaround, organizations running affected vCenter versions should treat patching and compromise assessment as urgent.
Sources
Broadcom VMware Security Advisory VMSA-2026-0006.2 and public security reports tracking active exploitation of CVE-2026-59310.







