Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAttackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter with a CVSS score of 9.8. The flaw allows attackers with network access to execute arbitrary code and gain persistent remote access to vCenter servers, though patches have been released.
AIThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has issued security patches for critical vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion products. The most severe flaw, CVE-2026-59309 with a CVSS score of 9.8, enables authentication bypass in VMware vCenter, allowing attackers with network access to potentially compromise the system. Organizations running these VMware products should prioritize applying these sec
