Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

By George Bailey   Published: 08/12/26   Updated: 08/12/26   3 min read

Attackers are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal flaw in VMware vCenter that can let a network-adjacent attacker execute arbitrary code and then persist on the appliance.

That should immediately move vCenter from maintenance-lane work into incident-lane work for any organization that still has exposed or poorly segmented management infrastructure.

What Changed

QUIRSO says it found successful compromise activity during incident response, not just background scanning. In the cases it investigated, the intrusion chain showed path traversal consistent with CVE-2026-59310 and then dropped a malicious cron job using reverse_ssh to maintain outbound persistence to attacker-controlled infrastructure.

The timing matters. Broadcom disclosed the flaw late last month, and QUIRSO saw victim systems reaching attacker infrastructure by August 3, roughly five days later. The company says it observed as many as 361 victim IPs across 47 countries, with especially high concentration in Germany, the U.S., Turkey, Iran, and France.

The reporting also notes a separate spike in scanning activity around CVE-2026-59309, another vCenter issue tied to unauthenticated authentication bypass in vmdir. The two campaigns are not yet conclusively linked, but the combined picture is clear: vCenter is under active attention right now.

Why CyberExperts Flagged It

vCenter compromise is rarely a contained event. It sits close to virtualization management, privileged workflows, and the operational backbone that many teams assume is already sufficiently isolated.

That assumption is exactly what makes stories like this dangerous. Even when defenders know vCenter is important, patching often slips because it touches core infrastructure and has a higher perceived change cost. Attackers benefit from that hesitation.

What Teams Should Do Next

Source context: CyberExperts is using The Hacker News as the primary reference for this update, including details attributed there to QUIRSO and Defused Cyber.

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading