TechNewsReel
Live

Global Campaign Exploits Critical VMware vCenter Flaw for Remote Code Execution

Threat actors are targeting a directory-traversal vulnerability in vCenter Server to establish persistent access across 47 countries.

TechNewsReel Newsroom · August 12, 2026

Threat actors are actively exploiting a critical vulnerability in VMware vCenter Server to execute arbitrary code and establish persistent remote access. The global campaign targets the central management plane of virtualized environments, posing a severe risk to enterprise infrastructure.

The attacks leverage CVE-2026-59310, a directory-traversal flaw located in the vCenter Server Syslog Server. According to the National Vulnerability Database, the vulnerability carries a CVSS v3.1 score of 9.8, reflecting its extreme severity. The flaw allows network-reachable attackers to bypass security boundaries and execute arbitrary code on the target system.

Security researchers at QUIRSO have tracked the scale of the intrusion, identifying 361 unique victim IP addresses spanning 47 different countries. The highest concentrations of compromised systems were detected in the United States, Germany, France, Turkey, and Iran. Telemetry indicates that the exploitation campaign began appearing around August 3, 2026.

Rapid Operationalization

The speed of the attack highlights a tightening window between patch release and active exploitation. Broadcom issued security advisory VMSA-2026-0006 on July 29, 2026, which provided fixes for CVE-2026-59310 and a separate authentication bypass flaw, CVE-2026-59309. The observed exploitation began just five days after the security update was made available, suggesting that threat actors rapidly operationalized the vulnerability once the patch revealed the flaw's nature.

Infrastructure Risks

Because vCenter serves as the primary management layer for virtualized workloads, a compromise at this level is catastrophic. Attackers who gain a foothold in vCenter possess high-privilege access to the entire virtual infrastructure. This allows them to target every hosted virtual machine, steal administrative credentials, and manipulate the underlying environment. Such access makes the vulnerability a prime target for advanced persistent threats (APTs) seeking long-term residency within a corporate network.

Current Outlook

Organizations are urged to apply the updates detailed in VMSA-2026-0006 immediately to close the directory-traversal gap. While the primary technical details of the vulnerability are confirmed, security teams should continue monitoring for signs of unauthorized remote access and outbound control channels. The rapid global spread of this campaign suggests that unpatched systems remain highly vulnerable to automated scanning and targeted intrusion.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.