Security News

Critical VMware vCenter Flaw Now Being Actively Exploited

Security Week · 13 Aug 2026
Key Takeaway If your business uses VMware vCenter, check with your IT provider immediately to confirm patches for CVE-2026-59310 have been applied.

Security researchers have confirmed that attackers are actively exploiting a critical vulnerability in VMware vCenter Server, the widely used platform for managing virtualised IT environments. The flaw, tracked as CVE-2026-59310, is a directory traversal bug that allows remote attackers to execute arbitrary code on vulnerable systems without needing physical access.

vCenter is commonly used by businesses and IT service providers to manage virtual machines and servers, meaning a successful attack could give hackers deep access to critical infrastructure, including customer data, internal systems, and connected networks. Because vCenter often sits at the centre of an organisation's virtual environment, a compromise here can have wide-reaching consequences beyond a single server.

While the source report does not detail the specific businesses affected or the exact exploitation method being used, the fact that attackers are already targeting this vulnerability in the wild significantly raises the urgency for organisations using VMware products to check their exposure and apply any available security updates as soon as possible.

VMware vCenter vulnerability patch management virtualisation security

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.