Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

Critical VMware vCenter Flaw Exploited: Update Now

A critical security vulnerability in VMware vCenter Server is being actively exploited by sophisticated attackers, who are using it to plant persistent backdoors inside businesses’ server infrastructure. If your organisation runs VMware for its virtualised servers, this needs your attention today.

What has happened

On 29 July 2026, Broadcom, which now owns VMware, published security advisory VMSA-2026-0006, patching five vulnerabilities across multiple VMware products. The most serious is CVE-2026-59310, a directory traversal flaw in the vCenter Server Syslog component, rated 9.8 out of 10 under the industry-standard CVSS scoring system. That puts it in the highest critical tier.

In plain terms: vCenter Server is the management console used to oversee virtualised server environments, where multiple virtual machines run on shared physical hardware. The flaw allows any attacker who can reach vCenter over a network, including, in many cases, over the internet, to send specially crafted requests that trick the system into running their own code, without needing a valid password or account. There is no configuration change that mitigates this. The only fix is to apply the patch.

Within five days of the patch being published, an advanced persistent threat (APT) actor, a well-resourced and highly capable attacker, often state-linked, began actively exploiting the flaw. Security researchers have since identified over 360 victim systems across 47 countries, with the vast majority compromised within the first two days of exploitation. The attack method is particularly serious: once inside, the attacker deploys a malicious scheduled task that installs a hidden reverse shell, an ongoing connection that lets the attacker return to the compromised server whenever they choose, even after a reboot.

This is not a theoretical risk. Attacks are happening right now.

Why it matters for your business

VMware vSphere and vCenter are used by businesses of all sizes to run virtualised server infrastructure, both on-premises and in co-location data centres. If your organisation hosts its own servers rather than relying entirely on cloud-hosted services, there is a reasonable chance vCenter is involved.

A successful compromise gives an attacker persistent, privileged access to your server environment, from which they can move to other systems on your network, exfiltrate sensitive data, deploy ransomware, or sit quietly for months gathering intelligence. The fact that a sophisticated APT actor is actively targeting this flaw makes early detection and response especially important.

The speed of exploitation also matters. Attackers are not waiting weeks after a patch is released before they act. In this case exploitation began within five days. As AI-assisted attack tooling continues to develop, that window is only getting shorter, a point we covered in our recent post on how AI is speeding up cyber attacks.

What to check and what to do

If you manage your own VMware infrastructure, take these steps without delay:

  • Find out what version you are running. Log in to the vCenter Server Appliance Management Interface (VAMI) and note your current version number.
  • Apply the VMSA-2026-0006 patch. For VMware vCenter Server 8.0, update to version 8.0 U3k. For VMware Cloud Foundation or vSphere Foundation, update to 9.1.0.0300 or 9.0.2.0100 as appropriate.
  • Restrict network access to vCenter. The management interface should not be directly reachable from the internet or from untrusted parts of your network. Segmenting your management plane from general traffic significantly reduces the risk from flaws like this. Our post on network segmentation for business leaders explains how this works in practice.
  • Check for signs of compromise. If your vCenter was reachable before the patch was applied, look for unexpected scheduled tasks or cron jobs (automated timed commands on the server), unfamiliar outbound network connections, and any processes associated with SSH tunnelling tools. If anything looks unusual, contact a specialist immediately rather than attempting to investigate alone.

How System Force IT can help

For clients whose infrastructure we manage, we are reviewing vCenter versions and prioritising this patch as part of our proactive patch management process. We track security advisories across all the platforms we support, so that updates like this one are identified and applied as quickly as possible, without you needing to monitor every vendor bulletin yourself.

That kind of proactive oversight is one of the core benefits of managed IT support. Most businesses do not have the bandwidth to track advisories from dozens of vendors, assess which patches are genuinely critical, and deploy them within days. When exploitation can begin within five days of a patch being published, a reactive approach simply is not fast enough.

If you would like to understand how we approach vulnerability management and infrastructure security for SMBs, take a look at our IT security services, or get in touch to discuss your specific setup.

If you would like help with any of this, get in touch at systemforce.co.uk/contact or call us on 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name