VMware vCenter flaw exploited in the wild, patch now

Threat actors are already exploiting a critical directory-traversal vulnerability in VMware vCenter to seize persistent remote control of enterprise servers, security researchers have found. The flaw, tracked as CVE-2026-59310 with a CVSS score of 9.8, allows any attacker with network access to execute arbitrary code on unpatched systems, potentially giving them full control over virtualized environments.
A race against time for IT teams
VMware released fixes for the bug in late July, but fresh telemetry from the threat-intelligence firm QUIRSO shows active exploitation in the wild. Because vCenter manages virtual machines across datacenters, a successful breach can ripple across an entire infrastructure, turning a single compromised host into a foothold for deeper intrusions.
Why patching must be immediate
The high severity score reflects both the ease of exploitation—no authentication required—and the potential blast radius. Once inside, attackers can install persistent backdoors, exfiltrate data, or pivot to other critical systems. VMware urges customers to upgrade to vCenter versions 8.0 U3b or 7.0 U3s immediately; delaying leaves production workloads exposed to automated attacks that probe for the flaw within hours of public disclosure.
Why it matters
This is not just another advisory—it is a live incident with real consequences. Organizations that delay patching risk silent persistence on their most sensitive servers, regulatory penalties for unpatched systems, and reputational damage from downstream breaches. Prioritize vCenter updates today; the window to prevent compromise is shrinking by the hour.
Source: The Hacker News. AI-assisted editorial synthesis — TechnoExpress.

