Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks

A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

ThreatVectr Newsdesk· 4 min read
A computer screen displaying Ubuntu Desktop with a lock symbol, symbolizing security vulnerability
Share

Key points

  • Attackers are actively exploiting CVE-2026-59310, a critical flaw in Broadcom's VMware vCenter server, security firm QUIRSO reported this week.
  • The bug carries a CVSS severity score of 9.8 out of 10 and lets an attacker with network access run their own code on the server.
  • Broadcom has released patches; unpatched customers face immediate risk to the systems that manage their virtual machines.
  • U.S. public companies that suffer a material intrusion via this flaw must file an SEC Form 8-K Item 1.05 within four business days of determining materiality.
  • EU operators covered by NIS2 face a 24-hour early warning duty under Article 23 of Directive (EU) 2022/2555.

Attackers are breaking into VMware vCenter servers through a recently patched flaw, and companies that run those servers now have both a technical problem and a legal clock ticking.

The flaw is tracked as CVE-2026-59310. It is a directory-traversal weakness, meaning an attacker can trick the server into reading or writing files outside the folders it is supposed to touch. From there, an intruder with network access can run their own code on the machine. It carries a severity rating of 9.8 out of 10.

Researchers at QUIRSO reported this week that criminals are already using the bug in real attacks. The Hacker News first flagged the exploitation activity.

vCenter is the console that administrators use to manage large fleets of virtual machines. Take over vCenter and you effectively hold the keys to a company's server room.

What is vCenter and why does this matter to non-technical readers?

vCenter is the control panel behind most corporate data centres. Hospitals, banks, airlines and retailers use it to run the invisible servers that power booking systems, payroll and patient records. If attackers seize that control panel, they can plant back doors that survive reboots, steal data, or push ransomware, the malicious software that locks files until a payment is made.

For an ordinary customer or patient, the immediate advice is simple. Watch for service outages or unusual account notifications from providers over the coming weeks, and treat any password-reset email you did not request as suspicious.

What are the affected products and fixes?

Broadcom has issued patches through its VMware Security Advisories channel. Administrators should apply the vendor-supplied update for their vCenter version without waiting for a maintenance window, given confirmed in-the-wild exploitation.

Item Detail
CVE ID CVE-2026-59310
Product Broadcom VMware vCenter Server
Flaw type Directory traversal leading to remote code execution
CVSS score 9.8 (Critical)
Status Patched by vendor; active exploitation reported

What are the disclosure duties if a company is hit?

A breach through this flaw is not just an IT event. It triggers filing obligations that vary by jurisdiction and sector, and the deadlines are short.

Under the U.S. Securities and Exchange Commission's final rule adopted in July 2023, public companies must disclose a material cybersecurity incident on Form 8-K, Item 1.05, within four business days of the materiality determination. The determination itself must be made "without unreasonable delay," per Item 1.05(a). This is a final rule, not a proposal, and it has been in force for filings since December 2023.

In the European Union, operators of essential and important entities under NIS2 must submit an early warning within 24 hours of becoming aware of a significant incident under Article 23(4)(a) of Directive (EU) 2022/2555, followed by a full incident notification within 72 hours. Member State transposition deadlines have now passed, though enforcement maturity varies.

U.S. critical infrastructure operators should also note CIRCIA. The Cybersecurity and Infrastructure Security Agency's proposed rule, published at 89 Fed. Reg. 23644 on 4 April 2024, would require covered entities to report covered cyber incidents within 72 hours. The comment period closed on 3 July 2024. It remains a proposed rulemaking; the final rule has not yet issued, and reporting duties do not bite until it does.

Boards and general counsel should assume that active exploitation of a 9.8-rated flaw in a system as central as vCenter will weigh heavily on any later materiality analysis.

© 2026 Threat Vectr