Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

A critical vulnerability affecting VMware vCenter, tracked as CVE-2026-59310, has been reported as being actively targeted by attackers. The flaw is described as a directory traversal bug that could enable remote attackers to execute arbitrary code on affected systems.
The vulnerability specifically impacts VMware vCenter, a centralized management platform for VMware vSphere environments. vCenter Server provides a single pane of glass for managing virtual machines, hosts, and other virtual infrastructure components. Given its central role in virtualized environments, a compromise of vCenter Server can have significant implications for an organization's entire virtual infrastructure.
The mechanism of a directory traversal vulnerability typically involves an attacker manipulating input to reference files or directories outside of an intended restricted directory. In this instance, the successful exploitation of CVE-2026-59310 allows for arbitrary code execution, which is a severe outcome. This means an attacker could potentially run malicious commands or scripts on the vCenter server, leading to full system compromise.
The scope of potential impact is broad, encompassing organizations that utilize VMware vCenter for managing their virtualized infrastructure. Products in this category are commonly deployed in enterprise and data center environments, making them attractive targets for adversaries seeking high-value assets. The "critical" designation often indicates a high severity score, reflecting the ease of exploitation and the potential impact.
Mitigation for this class of vulnerability typically involves applying vendor-provided patches or updates as soon as they become available. Organizations are generally advised to prioritize the deployment of security patches for critical vulnerabilities, especially when active exploitation is reported. Additionally, network segmentation, robust access controls, and continuous monitoring for suspicious activity on vCenter servers are recommended best practices.
While specific details about the ongoing attacks were not provided, the report underscores the persistent threat posed by critical vulnerabilities in widely used enterprise software. The rapid transition from vulnerability disclosure to active exploitation highlights the importance for organizations to maintain vigilant patch management practices and robust incident response capabilities to defend against evolving cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.