TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/Attackers Actively Exploit a Critical VMware vCenter Flaw in 47 Countries
News

Attackers Actively Exploit a Critical VMware vCenter Flaw in 47 Countries

A critical, unauthenticated VMware vCenter flaw tracked as CVE-2026-59310 is under active exploitation across 47 countries, and Broadcom says there is no workaround, only a patch.

August 13, 2026 3 Min Read
32

Attackers are actively exploiting a critical, unauthenticated remote code execution flaw in VMware vCenter, and the incident response firm that caught the campaign says it has already identified 361 victim IP addresses spread across 47 countries. Broadcom patched the bug, tracked as CVE-2026-59310, on July 29. Exploitation began just five days later, according to SecurityWeek and the German incident response firm QUIRSO, which first documented the activity.

Table Of Content

  • What CVE-2026-59310 Actually Does
  • A Second Critical Flaw Shipped in the Same Advisory
  • How Fast the Exploitation Campaign Moved
  • From Path Traversal to a Persistent Backdoor
  • What vCenter Administrators Should Do Now

What CVE-2026-59310 Actually Does

CVE-2026-59310 is a directory traversal vulnerability in the Syslog server component of VMware vCenter, the management console most VMware-based data centers use to run their virtual machine fleets. It carries a CVSS score of 9.8 out of 10. Broadcom’s own security advisory, VMSA-2026-0006.1, describes it plainly: a malicious actor with network access to vCenter can exploit the flaw to execute arbitrary code. Exploitation does not require any authentication, only network reach to the vCenter service, and no workaround exists, so patching is the only fix.

Broadcom credited the discovery to Phil Brass and Matt South of Atredis Partners. The fix landed in vCenter 9.1.0.0300, vCenter 9.0.2.0100, and vCenter 8.0 U3k or 8.0 U2f, covering VMware Cloud Foundation, VMware vSphere Foundation, and standalone vCenter Server deployments.

A Second Critical Flaw Shipped in the Same Advisory

The same July 29 advisory also patched CVE-2026-59309, a separate authentication bypass vulnerability in vCenter’s Directory Service that likewise scores 9.8 on the CVSS scale and shares the exact same affected versions and fixes. Quirso and SecurityWeek have so far only reported active exploitation of CVE-2026-59310, not CVE-2026-59309, but administrators patching one should patch both, since Broadcom ships the fixes together.

How Fast the Exploitation Campaign Moved

According to Quirso, the first confirmed connections from compromised vCenter servers back to attacker-controlled infrastructure appeared on August 3, just five days after Broadcom’s disclosure. The pace accelerated quickly from there: by August 4, 151 more victim IP addresses had shown up, and by August 5, 343 of the eventual 361 identified IPs, about 95 percent of the total, had already connected. Germany, the United States, Turkey, Iran, and France accounted for 185 of the 361 IPs between them, roughly half.

Quirso was careful to note that an IP address count is not the same as a count of victim organizations. “The exact number of victim organizations cannot be inferred from these IP addresses, as an IP address does not necessarily correspond to a unique company or physical system. Some addresses belong to hosting providers, cloud networks, or shared infrastructure,” the firm said.

From Path Traversal to a Persistent Backdoor

Quirso’s writeup describes a consistent attack chain: the attacker abuses the path traversal flaw to reach the Syslog service, plants a malicious cron job for persistence, and then installs reverse_ssh, an open source, Go-based SSH reverse-shell framework. Because reverse_ssh initiates an outbound connection back to attacker infrastructure, it slips past firewall rules that only block unsolicited inbound traffic. The Hacker News reported the same pattern: path traversal activity consistent with the flaw, followed by a cron job that establishes the reverse_ssh backdoor.

Quirso published a generic YARA rule on its GitHub so defenders can hunt for reverse_ssh builds on their own systems. The firm also cautioned that reverse_ssh has legitimate penetration-testing uses, so a detection alone is not proof of compromise; SecurityWeek reported that organizations with internet-facing vCenter systems should corroborate any hit with other signs, such as unauthorized installation locations and unexpected outbound connections.

What vCenter Administrators Should Do Now

There is no workaround for either CVE-2026-59310 or CVE-2026-59309, so the only remediation is applying Broadcom’s update:

  • vCenter 9.1.x: update to 9.1.0.0300
  • vCenter 9.0.x: update to 9.0.2.0100
  • vCenter 8.0: update to 8.0 U3k or 8.0 U2f

Given that the campaign compromised the vast majority of its eventual 361 victim IPs within 48 hours of first appearing, administrators running an affected version should treat this as an emergency change, not a routine maintenance window. Anyone who has not yet patched should also check for the reverse_ssh indicators Quirso published, since a vCenter server compromised before patching will still have the backdoor installed after the update is applied; patching closes the hole but does not remove an attacker who is already inside.

Tags:

broadcomCybersecurityvcentervmwareVulnerability Management

Share

A wall of individually numbered brass safe deposit boxes in a bank vault, each with its own separate keyhole
Previous Post

How to Isolate Per-User OAuth Tokens for a Multi-User AI Agent With Python and Ollama

Close-up photo of a clove hitch and square knot tied in rope and rigging aboard a sailing ship
Next Post

Microsoft’s MindTopo Benchmark Turns AI Spatial Reasoning Into a Planning Problem

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026