Cybersecurity researchers have identified active exploitation of a critical VMware vCenter Server vulnerability by a suspected Chinese state-sponsored threat actor. The flaw, tracked as CVE-2026-59310, carries a CVSS severity score of 9.8 and allows remote attackers to execute arbitrary code through directory-traversal techniques.
VMware vCenter Server serves as the centralized management platform for VMware virtualized environments, making it a high-value target for sophisticated threat actors. Broadcom, which acquired VMware in 2023, has released patches addressing this vulnerability. The exploitation by a China-nexus APT group suggests the flaw may be used for espionage or persistent access operations targeting enterprise infrastructure.
CVE-2026-59310 is a directory-traversal vulnerability that enables attackers to bypass security controls and access restricted files or directories on the vCenter server. By manipulating file paths, threat actors can potentially write malicious files to sensitive locations, leading to remote code execution. The severity rating reflects both the ease of exploitation and the privileged access attackers can gain once successful.
Organizations relying on VMware vCenter for infrastructure management face significant risk if systems remain unpatched. Successful exploitation could grant attackers administrative control over virtualized environments, enabling lateral movement, data theft, or deployment of additional malware. The involvement of a state-sponsored APT group indicates targeted campaigns rather than opportunistic attacks.
Security teams should prioritize applying Broadcom's patches for CVE-2026-59310 immediately. Administrators should also conduct thorough reviews of vCenter server logs for suspicious activity, unusual authentication attempts, or unexpected file modifications. Organizations should verify that vCenter servers are not directly exposed to the internet and implement network segmentation to limit potential attacker movement if compromise occurs.
Source: https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html


