VMware vCenter Flaw Is Being Exploited Across 47 Countries — Patch Now
A critical VMware vCenter vulnerability (CVE-2026-59310) is being actively exploited across 47 countries, with 361 compromised servers confirmed by security researchers. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 18 August.
The bug is a path-traversal flaw in vCenter’s Syslog server. An attacker with network access can exploit it to execute arbitrary code — no authentication required, CVSS 9.8. Once in, attackers are deploying reverse SSH tunnels and cron-job persistence to maintain long-term access. Broadcom released a patch on 29 July, but exploitation began just five days after public disclosure.
Why this matters for Australian businesses
If your business runs VMware virtualisation — and many Australian SMBs still do — vCenter is the control plane for everything: your VMs, your storage, your network config, your backups. An attacker who owns vCenter owns your entire virtual environment.
Here’s the problem we see regularly as an MSP: vCenter management interfaces left accessible from the internet because a NAT rule was set up during the original deployment and never removed. In regional environments especially — Central West NSW, the Northern Beaches — these legacy configurations often survive for years without an audit. If your vCenter is internet-facing and unpatched, you’re a sitting target right now.
What to do
Update to the patched vCenter version immediately — there is no workaround for this flaw. Then check whether your vCenter management interface is accessible from outside your network. If it is, restrict it to your management VLAN today, not next week.
If you’re unsure whether your VMware environment is exposed or up to date, get in touch — this is exactly the sort of thing our managed IT support team catches in routine infrastructure reviews.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
