ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
VMware vCenter directory traversal flaw (CVE-2026-59310) enables code execution
Source headline: Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat level
Critical
Signal strength
90/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
Attackers are actively exploiting a newly patched VMware vCenter vulnerability identified by QUIRSO. The flaw, CVE-2026-59310, is a directory-traversal issue that can be used by anyone with network access to the vCenter server. Successful exploitation can lead to arbitrary code execution, allowing attackers to establish persistent remote access. The issue is rated highly severe due to its high CVSS score. VMware customers should ensure vCenter systems are updated with the vendor patches and verify exposure controls and network access paths.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Open original source