Back to advisories

Global Threat Campaign Hits Critical VMware vCenter Flaw

Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.

CRITICALAdvisoryAug 14, 2026
Action required
Immediately scan all vCenter instances for indicators of compromise and persistence artifacts. Patch CVE-2026-59310 now, then conduct forensic analysis of vCenter logs and system files for signs of unauthorized access dating back to early this month.
Affected products
VMware vCenter Server