Critical Security Vulnerability Exploited in VMware vCenter
Attackers have begun actively exploiting a recently patched critical security vulnerability in Broadcom VMware vCenter. According to new findings from QUIRSO, this is the vulnerability CVE-2026-59310, which has been rated with a CVSS score of 9.8. This directory traversal vulnerability in the VMware vCenter Server allows a malicious actor with network access to execute arbitrary code. The vulnerability was discovered in version 7.0.3 of VMware vCenter and affects multiple configurations of the server. Attackers can not only gain temporary access through this vulnerability but also establish persistent backdoors that enable long-term control over affected systems.
Patches for this vulnerability were released on August 1, 2026. VMware has urgently urged all users to install the updates promptly to protect their systems. The security updates are available for all supported versions of VMware vCenter. Exploitation of this vulnerability could have significant impacts on businesses that use VMware vCenter to manage their virtual machines.
Experts warn that attackers could gain access to sensitive data and critical infrastructures through the vulnerability. QUIRSO's security research has shown that attacks have increased in recent days. Researchers have identified several campaigns targeting companies that use the affected software. These attacks utilize automated tools to exploit the vulnerability and gain access to the victims' networks. IT security officials are urged to regularly check their systems for signs of compromise.
Monitoring network activities and setting up Intrusion Detection Systems (IDS) can help detect unauthorized access early. Implementing security policies to minimize access to critical systems is also advisable. The VMware security vulnerability is not the first of its kind discovered in recent years. Similar vulnerabilities have been identified in other products, underscoring the need to install security updates promptly. Companies should also provide training for their employees to raise awareness of cyber threats.
The security community has already responded to the threat by disseminating information about the vulnerability and its exploitation. Security researchers and companies are collaborating to minimize the impact of the attacks and ensure the security of systems. The dissemination of information about the vulnerability is crucial to protect other companies from similar attacks. According to VMware, the vulnerability CVE-2026-59310 affects a wide range of systems worldwide. Companies using VMware vCenter should apply the security updates immediately to protect their systems. According to VMware, patches are available for all supported versions of vCenter.
💬 Comments (0)
No comments yet. Be the first to comment!