A critical vulnerability in VMware vCenter has been exploited by attackers, giving them persistent remote access to affected systems. VMware’s virtualization platform is used by over 500,000 organizations worldwide, including some of the largest enterprises and government agencies. This means that a significant number of companies are potentially vulnerable to this attack.
The vulnerability, tracked as CVE-2022-2156, was first disclosed in March 2022 but has only now been exploited in real-world attacks. VMware vCenter is a centralized management platform for virtualized environments, allowing administrators to monitor and manage multiple servers from a single interface. It uses the ESXi hypervisor and relies on a range of APIs and protocols to communicate with other systems.
Attackers are exploiting this vulnerability by targeting organizations that have not patched their vCenter installations. They gain access through a misconfigured or unpatched system, allowing them to remotely execute malicious code and maintain persistence even after initial access is lost. This means that attackers can potentially remain hidden in an organization’s network for an extended period.
The attack vector involves exploiting the vulnerability through a series of API calls, which can be made from outside the affected network. This makes it particularly difficult for organizations to detect and respond to these attacks. Once inside, attackers can move laterally across the network, compromising other systems and eventually gaining access to sensitive data or critical infrastructure.
The exploitation of this vulnerability highlights the ongoing threat posed by unpatched vulnerabilities in widely used software platforms like VMware vCenter. It also underscores the importance of maintaining up-to-date patch levels and conducting regular vulnerability assessments on critical systems. Furthermore, it emphasizes the need for organizations to implement robust security controls and monitoring practices to detect and respond to potential attacks.
In light of this attack, we recommend that all organizations using VMware vCenter take immediate action to assess their exposure and apply any available patches or updates. Regularly reviewing system configurations, patch levels, and network traffic can help identify potential vulnerabilities before they are exploited by attackers.
Source: The Hacker News — 2026-08-12