Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks

A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A server room with equipment racks, multiple screens displaying vulnerability scans and patch status dashboards, calendar or timeline showing urgent deadlines a
Share

Key points

  • Attackers are actively exploiting CVE-2026-59310, a critical flaw in Broadcom's VMware vCenter server, security firm QUIRSO reported this week.
  • The bug carries a CVSS severity score of 9.8 out of 10 and lets an attacker with network access run their own code on the server.
  • Broadcom has released patches; unpatched customers face immediate risk to the systems that manage their virtual machines.
  • U.S. Public companies that suffer a material intrusion via this flaw must file an SEC Form 8-K Item 1.05 within four business days of determining materiality.
  • EU operators covered by NIS2 face early warning and incident notification duties once a significant incident is confirmed.

Attackers are breaking into VMware vCenter servers through a recently patched flaw, and companies that run those servers now have both a technical problem and a legal clock ticking.

The flaw is tracked as CVE-2026-59310. It's a directory-traversal weakness, meaning an attacker can trick the server into reading or writing files outside the folders it's supposed to touch. From there, an intruder with network access can run their own code on the machine. It carries a severity rating of 9.8 out of 10.

Researchers at QUIRSO reported this week that criminals are already using the bug in real attacks. The Hacker News first flagged the exploitation activity.

VCenter is the console administrators use to manage large fleets of virtual machines. Take over vCenter and you effectively hold the keys to a company's server room. We first covered this CVE on 12 August 2026, and the shift from patched flaw to confirmed exploitation has happened fast.

What is vCenter and why does this matter to non-technical readers?

VCenter is the control panel behind most corporate data centres. Hospitals, banks and retailers use it to run the invisible servers that power booking systems, payroll and patient records. If attackers seize that control panel, they can plant back doors that survive reboots or push ransomware, the malicious software that locks files until a payment is made.

Our 30 July report on data centre exposure found roughly 32,000 infrastructure devices sitting just one network hop from the open internet. VCenter boxes are exactly the kind of high-value target that picture describes.

For an ordinary customer or patient, watch for service outages or unusual account notifications from providers over the coming weeks, and treat any password-reset email you didn't request as suspicious.

What are the affected products and fixes?

Broadcom has issued patches through its VMware Security Advisories channel. Administrators should apply the vendor-supplied update for their vCenter version without waiting for a maintenance window, given confirmed in-the-wild exploitation.

Item Detail
CVE ID CVE-2026-59310
Product Broadcom VMware vCenter Server
Flaw type Directory traversal leading to remote code execution
CVSS score 9.8 (Critical)
Status Patched by vendor; active exploitation reported

What are the disclosure duties if a company is hit?

A breach through this flaw isn't just an IT event. It triggers filing obligations that vary by jurisdiction, and the deadlines are short.

Under the SEC's final rule adopted in July 2023, public companies must disclose a material cybersecurity incident on Form 8-K, Item 1.05, within four business days of the materiality determination. The determination itself must be made "without unreasonable delay," per Item 1.05(a). This rule has been in force for filings since December 2023.

In the European Union, NIS2 operators of essential and important entities face a tiered notification duty: an early warning once a significant incident is identified, followed by a fuller notification within a short statutory window. Member State transposition deadlines have now passed, though enforcement maturity varies.

U.S. Critical infrastructure operators should also note CIRCIA. The Cybersecurity and Infrastructure Security Agency's proposed rule would require covered entities to report cyber incidents within a defined window after discovery. It remains a proposed rulemaking; reporting duties don't bite until a final rule issues.

Boards and general counsel should assume that active exploitation of a 9.8-rated flaw in a system as central as vCenter will weigh heavily on any later materiality analysis. The gap between "we knew" and "we filed" is where enforcement cases are built.

© 2026 Threat Vectr