Critical VMware vCenter flaw actively exploited in 47 countries

Critical VMware vCenter flaw actively exploited in 47 countries

Unspecified attackers are actively exploiting a critical 9.8 directory traversal flaw in VMware vCenter systems across 361 unique victim IP addresses in 47 countries, primarily in Germany, the United States, Turkey, Iran, and France.In an Aug. 10 blog post, German cybersecurity company Quirso, said a threat actor has been exploiting CVE-2026-59310 and using reverse secure shell (SSH) to maintain access to compromised systems, based on evidence compiled during a recent incident response case.A directory traversal vulnerability lets an attacker manipulate file paths to reach directories and files they should never touch, then execute code across and enterprise’s virtual environment.“Because vCenter serves as the nerve center of most organizations’ virtualization infrastructure, once it’s compromised, an attacker controls every virtual machine, every host, every snapshot in the environment,” said Denis Calderone, chief technology officer at Suzu Labs.Justin Beals, founder and…