CISA Warns of Actively Exploited VMware vCenter Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog.
Tracked as CVE-2026-59310, the flaw is a path traversal vulnerability that can potentially lead to arbitrary code execution on vulnerable vCenter deployments. CISA’s decision to add the vulnerability to its KEV catalog confirms that exploitation has been observed in real-world attacks.
The vulnerability deserves particular attention because VMware vCenter is not an ordinary application. It provides centralized management of virtual machines, hosts, storage and networking across virtualized environments.
If an attacker gains control of vCenter, the potential impact can extend far beyond a single vulnerable server.
For enterprise administrators, the immediate priority should be identifying all vCenter instances, checking their versions and determining whether management interfaces are accessible from untrusted networks.

Organizations should also review:
- VMware vCenter exposure,
- network segmentation,
- administrative accounts,
- privileged access,
- monitoring and logging,
- backup and recovery procedures,
- indicators of compromise.
The incident is another reminder that virtualization management infrastructure must be treated as a high-value security target.
A vulnerability in a management platform can potentially provide attackers with access to an entire virtualized environment rather than just one individual application.
CISA’s warning therefore deserves immediate attention from organizations running VMware infrastructure.
Patch the management layer before attackers turn it into a gateway to the rest of the infrastructure.






