VYPR
kevPublished Aug 13, 2026· Updated Aug 19, 2026· 4 sources

VMware vCenter Server Flaw Actively Exploited Days After Disclosure

A critical vulnerability in VMware vCenter Server, allowing for remote code execution, is being actively exploited by attackers just five days after Broadcom released security advisories.

VMware vCenter Server, a critical component for managing virtualized environments, has become the target of active exploitation following the disclosure of a severe vulnerability. Threat actors began exploiting the flaw a mere five days after Broadcom, the parent company of VMware, issued security advisories detailing the issue. This rapid exploitation highlights the shrinking window of opportunity for organizations to patch their systems before they fall victim to attacks.

The vulnerability, identified by its CVE identifier, allows for remote code execution (RCE) on affected vCenter Server instances. This means attackers can potentially run arbitrary code on the server without any prior authentication, granting them significant control over the compromised infrastructure. Such a capability is highly prized by malicious actors as it can be leveraged for a wide range of nefarious activities, including data theft, deploying ransomware, or using the compromised server as a pivot point to attack other systems within a network.

While the specific details of the exploit mechanism are not fully disclosed in the initial reports, the severity of RCE vulnerabilities in management platforms like vCenter cannot be overstated. These platforms often have privileged access to the entire virtualized environment, including sensitive data and critical business operations. Successful exploitation could lead to widespread disruption and compromise across an organization's IT infrastructure.

Broadcom's advisories, released on August 8, 2026, alerted users to the critical nature of the vulnerability and urged immediate action. However, the fact that exploitation was observed by August 13, 2026, indicates that threat actors were either aware of the vulnerability prior to its public disclosure or were exceptionally quick to develop and deploy exploits once the information became available. This rapid weaponization underscores the persistent threat landscape and the need for proactive security measures.

Organizations utilizing VMware vCenter Server are strongly advised to consult Broadcom's security advisories and apply the necessary patches or mitigations as soon as possible. The CISA (Cybersecurity and Infrastructure Security Agency) is expected to add this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog if it hasn't already, which would mandate federal agencies to patch within a specific timeframe. However, the current active exploitation suggests that the threat is not confined to federal networks.

The exploitation of this vCenter vulnerability serves as a stark reminder of the ongoing risks associated with unpatched software, particularly for widely used and critical infrastructure components. The speed at which vulnerabilities are being weaponized continues to increase, putting immense pressure on security teams to maintain vigilance and rapid response capabilities. This incident is likely to be closely monitored for further details on the threat actors involved and the full scope of the exploitation campaign.

The new reporting indicates that the exploitation campaign against CVE-2026-59310 in VMware vCenter Server has expanded globally and began earlier this month. While patches are available, the ongoing nature of the campaign suggests that simply applying updates may not be sufficient to fully remediate systems that have already been compromised.

This new report attributes the exploitation of CVE-2026-59310 to a suspected China-nexus APT, citing evidence such as Chinese-language artifacts in attacker scripts and operational patterns consistent with UTC+08:00 working hours. The campaign, which began shortly after public disclosure, has already impacted 361 IP addresses across 47 countries, with Germany, the U.S., and Turkey being heavily targeted. The attackers are deploying a Babuk-derived ransomware, identified as 'linuxFile', which provides remote command execution and establishes persistence via systemd and cron.

CISA has officially added CVE-2026-59310, a critical path traversal vulnerability affecting VMware vCenter, to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion signifies that the vulnerability is actively being exploited in the wild, prompting CISA to issue Binding Operational Directive 26-04, which mandates federal agencies to apply mitigations by August 21, 2026.

Synthesized by Vypr AI
VMware vCenter Server Flaw Actively Exploited Days After Disclosure · VYPR