Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

VMware vCenter Vulnerability Exposes Organizations to Persistent Remote Attacks

A critical vulnerability in VMware’s vCenter Server product has been exploited by attackers to gain persistent remote access to affected systems, potentially allowing them to move laterally within an organization and create a long-term threat. The exploit affects thousands of organizations worldwide that rely on vCenter for managing their virtual infrastructure.

The vulnerability, identified as CVE-2022-21574, is a critical one, rated 9.8 out of 10 by VMware. It allows attackers to bypass authentication and gain access to the vCenter Server using a malicious URL. Once inside, an attacker can move freely within the system, accessing sensitive data and potentially escalating their privileges. What’s more concerning is that this vulnerability can be exploited remotely, making it easy for attackers to launch attacks without any physical presence on the targeted network.

VMware has released patches to fix the issue, but many organizations have yet to apply them, leaving themselves exposed to potential attacks. Furthermore, the fact that this vulnerability was exploited in the wild suggests that attackers are already aware of its existence and are actively using it to breach systems. This highlights the importance of prompt patching and regular security updates.

The exploitation of this vulnerability is particularly insidious because it allows attackers to create a long-term presence within an organization’s network. Once inside, they can move laterally, accessing sensitive data and potentially creating backdoors for future attacks. This type of persistent threat can be difficult to detect and remove, making it essential for organizations to have robust security controls in place.

The fact that this vulnerability was exploited highlights the importance of regular security audits and penetration testing. These exercises can help identify vulnerabilities before they are exploited by attackers, reducing the risk of a breach. Furthermore, organizations should ensure that their security teams are trained to respond quickly and effectively to potential threats.

To protect themselves from this vulnerability, organizations should apply the latest patches as soon as possible and implement robust security controls to detect and prevent lateral movement within their networks. Regular security audits and penetration testing can also help identify vulnerabilities before they are exploited by attackers. By taking these steps, organizations can reduce the risk of a breach and protect themselves against persistent remote attacks.


Source: The Hacker News — 2026-08-12