Attackers are probing VMware vCenter after critical vulnerabilities were revealed, with DefusedCyber’s honeypots noting heightened vCenter fingerprinting activity This article explores vcenter environment attacker. . The activity includes requests to the /sdk/ endpoint using RetrieveServiceContent and exploration of the /websso single sign-on path.

While these requests do not indicate compromise, they suggest attackers are identifying exposed systems before launching more targeted attacks. The advisory covers five VMware vulnerabilities across vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products. Remote attackers with network access may bypass normal authentication to gain unauthorized access, making it a high-value target for the vCenter environment.

An attacker with control over it can modify virtual-machine configurations, generate accounts, alter network connections, gain access to disks, disrupt workloads, or use the platform to further penetrate an organization. DefusedCyber noted on X that researchers discovered CVE-2026-59310, a critical directory traversal vulnerability in the vCenter Syslog Server, which could permit network-based attackers to execute arbitrary code. Scanning often begins shortly after a critical disclosure; automated tools frequently search for vulnerable targets in response to such information.

Defenders should scrutinize web, reverse proxy, firewall, and vCenter logs for anomalous activity related to /sdk/ and /websso requests. They must investigate unusual authentication events, newly created accounts, altered permissions, suspicious virtual-machine activities, and unfamiliar management connections.