Threat Intelligence

Critical VMware vCenter Vulnerability Under Active Global Attack

Dark Reading · 14 Aug 2026
Key Takeaway If your business uses VMware vCenter, patch immediately and ask your IT provider to check for signs of compromise, not just apply the fix.

A critical vulnerability in VMware vCenter, tracked as CVE-2026-59310, is being actively exploited by attackers in a global campaign that began earlier this month. VMware vCenter is widely used by organisations to manage virtual servers and IT infrastructure, making this a significant concern for any business relying on virtualised environments.

What makes this threat particularly serious is that simply applying the available patch may not be enough to fully remove the risk. This suggests attackers may have already established footholds in some systems before or shortly after patches were released, meaning affected organisations could need additional steps to check for and remove any lingering compromise.

Businesses using VMware vCenter, including those that rely on managed service providers for IT infrastructure, should treat this as an urgent priority. Even organisations that believe they are not directly affected should confirm with their IT provider whether vCenter is in use anywhere in their environment.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.