Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Attackers are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to gain persistent remote access and execute arbitrary code.
Attackers are actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310 (CVSS 9.8), to gain persistent remote access, according to QUIRSO. The directory-traversal flaw in Broadcom's VMware vCenter server allows a malicious actor with network access to execute arbitrary code. Patches for the vulnerability were recently released.