Threat Intelligence

Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access

The Hacker News · 12 Aug 2026
Key Takeaway If your business or IT provider uses VMware vCenter, apply the latest security patch immediately and check whether your vCenter server is exposed to the internet unnecessarily.

Security researchers at QUIRSO have confirmed that a critical vulnerability in Broadcom's VMware vCenter Server is now being actively exploited by attackers in the wild. The flaw, tracked as CVE-2026-59310, carries a near-maximum severity score of 9.8 out of 10 and allows a malicious actor with network access to the vCenter server to execute arbitrary code without needing valid login credentials.

vCenter is widely used by businesses to manage virtualised servers and IT infrastructure, making it a high-value target for attackers. Once exploited, this type of vulnerability can allow criminals to establish persistent remote access, potentially giving them long-term control over critical systems even after the initial breach point is discovered. Patches for the vulnerability have already been released by Broadcom.

Any Australian business running VMware vCenter—whether managed in-house or through an IT provider—should treat this as an urgent priority. Attackers are known to move quickly once exploitation begins circulating publicly, scanning the internet for unpatched, exposed systems.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.