Attackers are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal flaw in VMware vCenter that can let a network-adjacent attacker execute arbitrary code and then persist on the appliance.
That should immediately move vCenter from maintenance-lane work into incident-lane work for any organization that still has exposed or poorly segmented management infrastructure.
What Changed
QUIRSO says it found successful compromise activity during incident response, not just background scanning. In the cases it investigated, the intrusion chain showed path traversal consistent with CVE-2026-59310 and then dropped a malicious cron job using reverse_ssh to maintain outbound persistence to attacker-controlled infrastructure.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.
The timing matters. Broadcom disclosed the flaw late last month, and QUIRSO saw victim systems reaching attacker infrastructure by August 3, roughly five days later. The company says it observed as many as 361 victim IPs across 47 countries, with especially high concentration in Germany, the U.S., Turkey, Iran, and France.
The reporting also notes a separate spike in scanning activity around CVE-2026-59309, another vCenter issue tied to unauthenticated authentication bypass in vmdir. The two campaigns are not yet conclusively linked, but the combined picture is clear: vCenter is under active attention right now.
Why CyberExperts Flagged It
vCenter compromise is rarely a contained event. It sits close to virtualization management, privileged workflows, and the operational backbone that many teams assume is already sufficiently isolated.
That assumption is exactly what makes stories like this dangerous. Even when defenders know vCenter is important, patching often slips because it touches core infrastructure and has a higher perceived change cost. Attackers benefit from that hesitation.
What Teams Should Do Next
- Patch CVE-2026-59310 on every vCenter instance you still run, and treat any delay as a documented risk decision rather than routine backlog.
- Check whether any vCenter management interfaces are reachable from broader internal networks or, worse, the internet. If exposure exists, reduce it immediately while patching proceeds.
- Hunt for unexpected outbound SSH behavior, unauthorized cron jobs,
reverse_sshartifacts, and other persistence mechanisms on vCenter appliances. - Review logs for suspicious access beginning shortly after Broadcom’s public disclosure window, especially around path traversal, shell execution, or appliance configuration changes.
- Keep a separate watch on CVE-2026-59309 scanning because defenders should not assume the only relevant vCenter pressure this week is the already-confirmed 59310 exploitation chain.
Source context: CyberExperts is using The Hacker News as the primary reference for this update, including details attributed there to QUIRSO and Defused Cyber.
See this item in The 5-Minute Cyber Brief