Threat actors have begun exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, according to QUIRSO researchers. The flaw carries a CVSS score of 9.8 and allows attackers with network access to execute arbitrary code on affected systems, establishing persistent remote access to enterprise infrastructure.
VMware released patches for this vulnerability, but organizations running unpatched vCenter instances remain exposed. Directory-traversal flaws enable attackers to bypass access controls and navigate the file system to reach sensitive components. In vCenter's case, successful exploitation grants complete code execution privileges, effectively handing attackers the keys to virtualized environments.
The active exploitation poses immediate risk to organizations managing on-premises or hybrid cloud infrastructure. vCenter controls virtual machines, resource allocation, and security policies across data centers. Compromised instances allow attackers to pivot laterally across virtualized workloads, exfiltrate data from hosted applications, deploy ransomware across VM environments, or establish backdoors for persistent access.
The timing matters here. Broadcom acquired VMware in late 2023, and security disclosure practices shifted. Organizations often face delays between patch release and deployment, creating exploitation windows. Attackers monitor these gaps methodically. Network-accessible vCenter servers without restrictive access controls represent high-value targets.
Organizations should treat this as urgent. Immediate actions include identifying internet-facing vCenter instances, applying available patches across all vCenter deployments, and restricting network access to vCenter through firewalls and VPN requirements. Monitor vCenter logs for suspicious activities, including failed authentication attempts, unusual administrative accounts, or unexpected code execution.
Given the high CVSS score and active exploitation, this vulnerability ranks among the most dangerous vCenter issues disclosed. The shift from theoretical risk to active attacks compresses response timelines. Organizations without patch management processes
