Attackers are exploiting critical VMware vCenter flaw CVE-2026-59310, with 361 victim IP addresses identified across 47 countries.

Threat actors are actively exploiting a critical vulnerability in Broadcom’s VMware vCenter Server, with researchers identifying hundreds of potentially compromised systems across dozens of countries.
The vulnerability, tracked as CVE-2026-59310, is a directory-traversal flaw in the VMware vCenter Server Syslog server. Broadcom rates the vulnerability as critical with a CVSS score of 9.8 and says an attacker with network access could exploit it to execute arbitrary code.
Broadcom publicly disclosed the vulnerability on July 29, 2026, and released patches to address it. Researchers at German cybersecurity company QUIRSO subsequently identified exploitation activity against vulnerable vCenter systems.
According to QUIRSO, compromised systems first established contact with attacker-controlled domains on August 3, just five days after Broadcom disclosed the vulnerability. Researchers identified as many as 361 unique victim IP addresses across 47 countries.
The largest numbers of observed victim IP addresses were located in Germany, the United States, Turkey, Iran and France. However, the number of IP addresses does not necessarily represent the same number of individual organizations.
The observed attack chain included activity consistent with exploitation of the directory-traversal flaw, followed by the deployment of a malicious cron job. Attackers used reverse_ssh, an open-source tool that can establish SSH connections to infrastructure controlled by an attacker, to maintain access to compromised systems.
QUIRSO said the timing of the activity strongly suggests that the public disclosure of CVE-2026-59310 may have provided the starting point for the campaign, although the researchers noted that the attacker could potentially have known about the vulnerability beforehand.
The identity of the threat actor remains unknown. QUIRSO believes the activity is consistent with a suspected advanced persistent threat (APT) actor.
VMware infrastructure has previously been targeted by sophisticated threat groups, including China-linked actors, but there is currently not enough evidence to attribute this particular campaign to a known group.
Another critical VMware vCenter vulnerability, CVE-2026-59309, has also attracted scanning activity. That vulnerability is different from CVE-2026-59310: it is an authentication-bypass flaw in VMware Directory Service. Broadcom also rates CVE-2026-59309 as critical with a CVSS score of 9.8.
Researchers have cautioned that the scanning observed for CVE-2026-59309 should not automatically be linked to the attackers exploiting CVE-2026-59310. The available evidence does not establish that the two activities are part of the same campaign.
QUIRSO also warned that the presence of reverse_ssh alone should not be considered proof of compromise. However, its presence alongside unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance should be treated as a high-priority indicator for investigation.
The campaign highlights how quickly attackers can move after critical vulnerabilities affecting widely deployed enterprise software become public. Organizations running affected VMware vCenter systems should apply Broadcom’s available security updates and investigate their environments for signs of unauthorized access or persistence.
Source: The Hacker News and Broadcom
Related articles :
- Wakefield Man Jailed for Abuse of Seven Children
- Man Jailed 9 Years for Rape and Stalking in Manchester
- Buffalo Priest Charged in Child Abuse Material Case
Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.






