Attackers are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal flaw in VMware vCenter that can let a network-adjacent attacker execute arbitrary code and then persist on the appliance.
That should immediately move vCenter from maintenance-lane work into incident-lane work for any organization that still has exposed or poorly segmented management infrastructure.
What Changed
QUIRSO says it found successful compromise activity during incident response, not just background scanning. In the cases it investigated, the intrusion chain showed path traversal consistent with CVE-2026-59310 and then dropped a malicious cron job using reverse_ssh to maintain outbound persistence to attacker-controlled infrastructure.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The timing matters. Broadcom disclosed the flaw late last month, and QUIRSO saw victim systems reaching attacker infrastructure by August 3, roughly five days later. The company says it observed as many as 361 victim IPs across 47 countries, with especially high concentration in Germany, the U.S., Turkey, Iran, and France.
The reporting also notes a separate spike in scanning activity around CVE-2026-59309, another vCenter issue tied to unauthenticated authentication bypass in vmdir. The two campaigns are not yet conclusively linked, but the combined picture is clear: vCenter is under active attention right now.
Why CyberExperts Flagged It
vCenter compromise is rarely a contained event. It sits close to virtualization management, privileged workflows, and the operational backbone that many teams assume is already sufficiently isolated.
That assumption is exactly what makes stories like this dangerous. Even when defenders know vCenter is important, patching often slips because it touches core infrastructure and has a higher perceived change cost. Attackers benefit from that hesitation.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What Teams Should Do Next
- Patch CVE-2026-59310 on every vCenter instance you still run, and treat any delay as a documented risk decision rather than routine backlog.
- Check whether any vCenter management interfaces are reachable from broader internal networks or, worse, the internet. If exposure exists, reduce it immediately while patching proceeds.
- Hunt for unexpected outbound SSH behavior, unauthorized cron jobs,
reverse_sshartifacts, and other persistence mechanisms on vCenter appliances. - Review logs for suspicious access beginning shortly after Broadcom’s public disclosure window, especially around path traversal, shell execution, or appliance configuration changes.
- Keep a separate watch on CVE-2026-59309 scanning because defenders should not assume the only relevant vCenter pressure this week is the already-confirmed 59310 exploitation chain.
Source context: CyberExperts is using The Hacker News as the primary reference for this update, including details attributed there to QUIRSO and Defused Cyber.
See this item in The 5-Minute Cyber Brief
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Coder’s registry infrastructure compromised to push malicious modules
The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no longer verifying...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes defenders already...
HPE patches critical ArubaOS-CX remote code execution flaw
ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation arrives. A...
Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.