VMware and Cisco Zero-Day Vulnerabilities Exploited Globally

VMware and Cisco Zero-Day Vulnerabilities Exploited Globally

First seen 25 Aug 2026, 06:50 UTC Tech-Insider 77.0

Article Content

Browse articles
ThreatCluster

Two significant zero-day vulnerabilities have emerged, affecting VMware vCenter and Cisco ASA/FTD systems. CVE-2026-59310, published on July 30, 2026, is actively exploited in 47 nations, with a proof-of-concept released on August 17, 2026. Meanwhile, CVE-2026-20349, disclosed on August 11, 2026, is also under active exploitation as confirmed by CISA on the same day. Both vulnerabilities have been added to the CISA KEV list, indicating their critical nature. The VMware vulnerability allows attackers to execute arbitrary code, while the Cisco flaw has a CVSS score of 8.6, indicating high severity. Organizations using affected systems are urged to take immediate action to mitigate risks. The scope of impact is extensive, affecting numerous organizations globally.

Key Points: • CVE-2026-59310 affects VMware vCenter, exploited in 47 nations. • CVE-2026-20349 targets Cisco ASA/FTD with a CVSS score of 8.6. • Both vulnerabilities are actively exploited and listed in CISA's KEV catalog.

Timeline

2026-07-30
CVE-2026-59310 published
VMware disclosed a critical vulnerability in vCenter, allowing arbitrary code execution.
Tech-Insider
2026-08-11
CVE-2026-20349 published
Cisco announced a zero-day vulnerability in ASA/FTD systems with a CVSS score of 8.6.
Tech-Insider
2026-08-11
CVE-2026-20349 added to CISA KEV
CISA confirmed active exploitation of the Cisco vulnerability on the same day it was published.
Tech-Insider
2026-08-17
First public PoC for CVE-2026-59310
A proof-of-concept for the VMware vCenter vulnerability was made publicly available.
Tech-Insider
2026-08-18
CVE-2026-59310 added to CISA KEV
CISA listed the VMware vulnerability as actively exploited, highlighting its critical nature.
Tech-Insider