Global Threat Campaign Hits Critical VMware vCenter Flaw

2026-08-14T02:51:34Z666101dd8e8bd6d730c584c89f66efe7aac4aee6d29ca1b832593b37a98c54f5
CVE-2026-18577CVE-2026-59310CVE-2026-62878active-exploitationai-agent-hijackingai-securityaptcritical-infrastructurecryptocurrency-theftdata-theftdevice-code-phishingfortinetics-otidentity-and-access-managementmetabasemfa-bypassn-able-rmmphishingprompt-injectionransomwarercesandbox-escapesupply-chain-securityvishingvmware-vcentervulnerabilitywater-systemswindows-dns-server

What happened

Dark Reading coverage highlights active exploitation of critical vulnerabilities, ransomware and data-theft campaigns, attacks against critical infrastructure, identity and authentication weaknesses, and emerging AI-agent and AI-browser security risks. Notable issues include exploitation of VMware vCenter CVE-2026-59310, Windows DNS Server RCE CVE-2026-62878, Fortinet flaws used to bypass MFA, N-able RMM authentication bypass CVE-2026-18577, and a Metabase zero-day reportedly enabling remote administrator access. The feed also describes widespread phishing, cloud and SaaS data exposure, mobile

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
666101dd8e8bd6d730c584c89f66efe7aac4aee6d29ca1b832593b37a98c54f5
Enrichment time
2026-08-14T02:51:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.