Global Threat Campaign Hits Critical VMware vCenter Flaw

A global threat campaign is actively exploiting a critical VMware vCenter vulnerability (CVE-2026-59310), with attacks beginning earlier this month; patching may not be sufficient to fully mitigate the risk.

A global threat campaign is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310. Exploitation began earlier this month. Security experts warn that patching the flaw may not be sufficient to fully mitigate the risk, as attackers may have already established persistence. Organizations using affected VMware vCenter versions should urgently apply patches and conduct thorough compromise assessments.