← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 13:58via Cyber Security News

Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access

Brief

An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks.

Tracked as CVE-2026-59310 , the flaw is a maximum-severity directory-traversal vulnerability residing in the VMware vCenter Syslog server component.

VMware vCenter Systems Exploited for Remote Access

Broadcom released a security advisory warning that unauthenticated attackers with network access to an exposed vCenter instance can exploit the vulnerability to achieve remote code execution (RCE) with system privileges.

Read more on Cyber Security News