CISA Warns of VMware vCenter Path Traversal Vulnerability Actively Exploited in Attacks
Key Takeaways The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding active exploitation of CVE-2026-59310, a path traversal vulnerability in...
Key Takeaways
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding active exploitation of CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter.
- This flaw allows attackers with network access to a vulnerable vCenter instance to execute arbitrary code, posing a severe risk to virtual infrastructure.
- CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply mitigations by August 21, 2026.
- Organizations must immediately identify and secure all vCenter deployments, prioritizing vendor-supplied patches and robust access controls.
CISA Flags Actively Exploited VMware vCenter Path Traversal Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated warnings concerning a critical vulnerability within Broadcom’s VMware vCenter, identified as CVE-2026-59310. The agency recently added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, citing concrete evidence of its active exploitation in ongoing attacks.
Table Of Content
This vulnerability, categorized as a path traversal issue under CWE-22, impacts VMware vCenter. CISA’s assessment indicates that an adversary with network access to a susceptible vCenter instance can leverage this flaw to achieve arbitrary code execution. Such an exploit presents a significant threat to organizations relying on VMware virtual infrastructure, particularly where vCenter servers are exposed to untrusted networks or compromised internal accounts provide access.
Understanding Path Traversal Vulnerabilities
Path traversal vulnerabilities emerge when applications fail to adequately validate file paths provided by users. Attackers can craft specific path values to bypass intended access controls, thereby gaining unauthorized access to files or directories outside their designated locations. In the context of CVE-2026-59310, successful exploitation could enable an intruder to circumvent standard security measures and execute code directly within the vCenter environment.
VMware vCenter servers represent exceptionally high-value targets due to their central role in managing virtual machines, hosts, datastores, networking configurations, and access controls across an entire virtualized environment. An attacker who gains control over a vCenter server can potentially disrupt numerous workloads, modify virtual machine settings, deploy malicious virtual machines, exfiltrate credentials, or disable critical recovery operations.
CISA Mandates Swift Remediation
CISA officially added CVE-2026-59310 to its KEV catalog on August 18, 2026. Federal civilian executive branch agencies are now under a strict mandate, outlined in Binding Operational Directive 26-04, to implement necessary mitigations by August 21, 2026. This compressed remediation timeline underscores the severe risk posed by the active exploitation of critical infrastructure management systems.
The agency advises all organizations to promptly apply mitigations in accordance with Broadcom’s official vendor instructions. Furthermore, CISA stresses the importance of thoroughly evaluating every affected asset for internet exposure. Organizations must also align their security update prioritization with CISA’s BOD 26-04 guidance and adhere to its forensics triage requirements. In instances where no mitigations are available, CISA recommends discontinuing the use of the vulnerable product.
While CISA has not explicitly stated whether CVE-2026-59310 has been leveraged in ransomware campaigns, VMware management platforms are consistently targeted in enterprise intrusions. Their comprehensive control over virtualized environments makes them attractive entry points for adversaries seeking broad system access and disruption.
What You Should Do
- Identify All vCenter Deployments: Immediately locate and inventory all VMware vCenter instances within your environment.
- Verify Software Versions: Determine the exact software versions of all identified vCenter deployments to ascertain vulnerability status.
- Assess Exposure: Determine if any vulnerable vCenter systems are reachable from the internet or from less-trusted internal network segments.
- Apply Vendor Patches: Prioritize and apply all available patches and updates from Broadcom/VMware as soon as they are released.
- Restrict Management Access: Limit management access to vCenter servers to only approved, secure networks and enforce strict network segmentation.
- Enforce Multi-Factor Authentication (MFA): Implement and enforce MFA for all privileged vCenter accounts.
- Audit Privileged Accounts: Regularly review and audit all privileged vCenter accounts for any unauthorized access or suspicious activity.
- Monitor Logs: Continuously inspect vCenter, hypervisor, identity, and network logs for suspicious authentication events or abnormal administrative actions.
- Preserve Logs for Forensics: If compromise is suspected, preserve all relevant vCenter, hypervisor, identity, and network logs before applying patches to facilitate forensic analysis.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.