
CVE-2026-59310: VMware vCenter — Global Remote Code Execution Risk (July 2026)
CVE-2026-59310 — VMware vCenter
CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter, rated CVSS 9.8. The flaw enables unauthenticated attackers to execute arbitrary code on affected servers. Public exploitation began within days of disclosure, with APT actors leveraging this bug for persistent remote access.
Attack Vector
Attackers exploit CVE-2026-59310 by sending crafted HTTP requests that traverse directories and drop malicious payloads on vCenter servers. Successful exploitation provides shell-level access, allowing adversaries to establish reverse shells and maintain persistence. Over 360 victim IPs in 47 countries have been observed compromised. Indicators of compromise include unusual outbound connections from vCenter hosts and unauthorized shell processes.
Who Is at Risk
All organizations running unpatched VMware vCenter deployments are at immediate risk. Both on-premises and cloud-managed vCenter instances are vulnerable. Confirmed victims span critical infrastructure, finance, healthcare, and managed service providers globally.
Patch & Mitigate
- Patch: Apply the official VMware vCenter patch released July 29, 2026, without delay.
- Workaround: No reliable workaround is available; patching is mandatory.
- Detect: Monitor for unexpected outbound connections from vCenter servers, new or suspicious shell processes, and review logs for directory traversal attempts in HTTP requests.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploit the directory traversal bug to gain entry.
- TA0008 — Lateral Movement: Gained access may be leveraged to pivot within the network.
- TA0009 — Collection: Persistent shells enable ongoing data access and exfiltration.
Source: https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

