Apply VMware's security updates for CVE-2026-59310 immediately. Implement additional defensive measures as recommended by VMware to complement patching. Monitor for anomalous activity on vCenter Server systems. Review VMware's advisory for supplementary guidance on hardening affected deployments.
Quick answers
What is CVE-2026-59310?
Apply VMware's security updates for CVE-2026-59310 immediately. Implement additional defensive measures as recommended by VMware to complement patching. Monitor for anomalous activity on vCenter Server systems. Review VMware's advisory for supplementary guidance on hardening affected deployments.
How severe is CVE-2026-59310?
high, CVSS 9.8
Is CVE-2026-59310 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-59310 be mitigated?
Apply VMware's security updates for CVE-2026-59310 immediately. Implement additional defensive measures as recommended by VMware to complement patching. Monitor for anomalous activity on vCenter Server systems. Review VMware's advisory for supplementary guidance on hardening affected deployments.
CVSS
9.8
Vendor
VMware
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
vCenter
Mitigation
Apply VMware's security updates for CVE-2026-59310 immediately. Implement additional defensive measures as recommended by VMware to complement patching. Monitor for anomalous activity on vCenter Server systems. Review VMware's advisory for supplementary guidance on hardening affected deployments.
On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The additions include a Microsoft IKE Service Extensions double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal, and an macOS improper authentication issue. CISA's Binding Operational Directive 26-04 reinforces rapid remediation requirements for Federal Civilian Executive Branch agencies on publicly exposed assets.
Security researchers and VMware have confirmed active exploitation of CVE-2026-59310, a critical flaw in vCenter Server. The vulnerability, disclosed on August 13, 2026, allows remote attackers to gain unauthorized access and control over affected systems. While patching is recommended, analysts warn it may not be sufficient to fully remediate the active threat campaign targeting deployments worldwide.