CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Broadcom VMware vCenter vulnerability, tracked as CVE-2026-59310 , to its Known Exploited Vulnerabilities catalog after evidence showed active exploitation in attacks.
The flaw affects VMware vCenter and is classified as a path traversal vulnerability under CWE-22. According to CISA, an attacker with network access to a vulnerable vCenter instance could exploit the issue to execute arbitrary code.
This poses a serious risk to organizations running VMware virtual infrastructure, particularly when vCenter servers are exposed to untrusted networks or accessible via compromised internal accounts.
Path traversal flaws occur when an application fails to validate user-provided file paths properly. An attacker may abuse specially crafted path values to access files or directories outside the intended location.
VMware vCenter Path Traversal Vulnerability Exploited
In this case, successful exploitation could allow an intruder to bypass normal access controls and gain code execution on the vCenter environment.
VMware vCenter is a high-value target because it centrally manages virtual machines, hosts, datastores, networking, and access controls.
Attackers who gain control of a vCenter server may be able to disrupt many workloads, change virtual machine settings, deploy malicious virtual machines, steal credentials, or turn off recovery operations.
CISA added CVE-2026-59310 to the KEV catalog on August 18, 2026. Federal civilian executive branch agencies must apply required mitigations by August 21, 2026, under Binding Operational Directive 26-04. The short remediation window reflects the risk posed by the exploitation of vulnerable infrastructure management systems.
The agency said organizations should apply mitigations in line with Broadcomโs vendor instructions and evaluate every affected asset for internet exposure.
Organizations must also follow CISAโs BOD 26-04 guidance for prioritizing security updates based on risk, as well as its forensics triage requirements. Where mitigations are not available, CISA advises affected stakeholders to discontinue use of the vulnerable product.
CISA has not indicated whether CVE-2026-59310 has been used in ransomware operations. However, VMware management platforms have repeatedly been targeted in enterprise intrusions because they offer attackers broad control over virtualized environments.
Security teams should immediately identify all vCenter deployments , confirm their software versions, and determine whether exposed systems are reachable from the internet or from less-trusted internal network segments.
Administrators should restrict management access to approved networks, enforce multi-factor authentication, review privileged vCenter accounts, and inspect logs for suspicious authentication events or abnormal administrative activity.
Organizations should also preserve relevant vCenter, hypervisor, identity, and network logs before patching if compromise is suspected. Rapid containment and forensic review are important because a successful attack against a virtualization management platform can have consequences across the entire data center.
ย Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations.ย ->ย Integrate ANY.RUN With Your SOCย Now .
The post CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News .
cybersecuritynews.com