Skip to content

Global attack campaign exploits critical vulnerability in VMware vCenter

Since the beginning of the month, the critical vulnerability CVE-2026-59310 in VMware vCenter has been actively exploited as part of a worldwide attack campaign. According to the report, simply applying the patch may not be enough to fully eliminate the threat.

The vulnerability identified as CVE-2026-59310 affects VMware vCenter, the central management platform for VMware virtualization environments. According to Dark Reading, active exploitation of the flaw began as early as the beginning of the month and is occurring as part of a globally observed campaign, rather than as an isolated incident.

For CISOs, it is relevant that vCenter instances typically have far-reaching administrative access to virtual infrastructures. A successful compromise can therefore give attackers control over numerous virtual machines and the underlying infrastructure. The fact that this is a critical vulnerability that is already being actively exploited increases the urgency for affected organizations.

Of particular note is the indication that simply applying the vendor’s patch may not be sufficient to fully mitigate the threat. This suggests that already compromised systems may require additional remediation measures, such as checking for persistence mechanisms or prior access that go beyond patching. Affected environments should therefore not only check their patch status but also search for indicators of prior compromise.

The critical VMware vCenter flaw CVE-2026-59310 has been actively exploited worldwide since the beginning of the month, and according to the report, patching alone may not fully eliminate the threat.


Source: www.darkreading.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: