Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access
Security researchers at QUIRSO have confirmed that a critical vulnerability in Broadcom's VMware vCenter Server is now being actively exploited by attackers in the wild. The flaw, tracked as CVE-2026-59310, carries a near-maximum severity score of 9.8 out of 10 and allows a malicious actor with network access to the vCenter server to execute arbitrary code without needing valid login credentials.
vCenter is widely used by businesses to manage virtualised servers and IT infrastructure, making it a high-value target for attackers. Once exploited, this type of vulnerability can allow criminals to establish persistent remote access, potentially giving them long-term control over critical systems even after the initial breach point is discovered. Patches for the vulnerability have already been released by Broadcom.
Any Australian business running VMware vCenter—whether managed in-house or through an IT provider—should treat this as an urgent priority. Attackers are known to move quickly once exploitation begins circulating publicly, scanning the internet for unpatched, exposed systems.