Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Reported exploitedVMware vCentervCenter Syslog ServerOur summary
Broadcom addressed a critical remote code execution flaw in VMware vCenter, tracked as CVE-2026-59310, following its disclosure on July 29. Quirso reported that an advanced persistent threat actor is actively exploiting this directory traversal vulnerability to deploy reverse shells for persistent access. The campaign targets exposed systems across 47 countries, with initial compromises observed shortly after the security bulletin was published.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.