GBHackers

CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog.

The vulnerability, tracked as CVE-2026-59310, is a path traversal flaw that enables arbitrary code execution in affected vCenter deployments.

VMware vCenter Path Traversal Flaw

CVE-2026-59310 impacts the VMware vCenter Syslog Server component and corresponds to CWE-22, which involves improper restrictions on directory pathnames.

An attacker with network access to a vulnerable vCenter instance could exploit this flaw to traverse directories beyond their intended location and execute malicious code. Security reports classify this vulnerability as a critical unauthenticated remote code execution risk, assigning it a CVSS score of 9.8.

The seriousness of this flaw stems from vCenter’s role as a central management hub for virtualized infrastructure. If compromised, an attacker could gain a strategic foothold to access virtual machines, modify configurations, establish persistence, steal credentials, or facilitate lateral movement across an enterprise environment.

Reports indicate that attackers exploiting this vulnerability have utilized reverse SSH tools to maintain persistent remote access after compromising exposed vCenter appliances.

CISA added CVE-2026-59310 to the KEV Catalog on August 18, 2026, with a remediation deadline set for August 21 for affected federal civilian executive branch agencies.

The agency has instructed organizations to implement mitigations in accordance with vendor guidance, consider internet exposure, adhere to applicable BOD 26-04 risk-based patching requirements, and conduct necessary forensic triage.

In cases where mitigations are unavailable for cloud services, CISA advises stakeholders to follow relevant guidance or discontinue use of the affected product.

Broadcom released fixes for the vulnerability on July 29, 2026. Reports indicate that exploitation began within days of the disclosure, highlighting the short window defenders have to respond once an effective exploit is available.

Researchers have identified hundreds of potentially affected public-facing systems across multiple countries. However, CISA’s KEV entry does not confirm any ransomware activity associated with this vulnerability.

Organizations should promptly identify all vCenter Server deployments, prioritize internet-facing and externally reachable instances, and apply Broadcom’s patched releases.

Security teams should also review appliance logs, authentication events, process activities, network connections, and recent administrative changes for signs of compromise.

Given the critical nature of vCenter, organizations should treat unpatched and exposed systems as potentially compromised until incident-response triage can clarify the situation.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link