
Menace actors have begun to actively exploit a not too long ago patched crucial safety flaw in Broadcom VMware vCenter, in response to new findings from QUIRSO.
The vulnerability in query is CVE-2026-59310 (CVSS rating: 9.8), a directory-traversal vulnerability within the VMware vCenter server {that a} malicious actor with community entry can exploit to execute arbitrary code. Patches for the flaw have been launched by Broadcom late final month.
The German cybersecurity firm stated it found the exercise following an incident response engagement. The assault chain is claimed to have exhibited path traversal exercise in step with the flaw, adopted by the deployment of a malicious cron job to ascertain persistence on the host utilizing reverse_ssh, an open-source instrument used for establishing SSH connections to risk actor-controlled infrastructure.
Compromised programs recognized by QUIRSO have been discovered to first set up contact with the attacker’s domains on August 3, 5 days after Broadcom publicly disclosed the failings. In all, there are as many as 361 distinctive sufferer IP addresses positioned throughout 47 international locations. Most of them are positioned in Germany, the U.S., Turkey, Iran, and France.
“Whereas the attacker might need had prior data of the vulnerability, the sturdy correlation between the time of disclosure and exploitation suggests the disclosure because the preliminary place to begin for the marketing campaign,” QUIRSO added.
It isn’t clear who’s behind the exploitation marketing campaign, but it surely’s believed to be the work of a suspected superior persistent risk (APT) actor.
It is value mentioning that VMware home equipment have been a profitable goal for Chinese language risk actors like UNC5174, who’ve weaponized safety flaws impacting VMware Instruments and VMware vCenter in varied espionage campaigns.
In April 2025, SentinelOne disclosed particulars of a risk cluster dubbed PurpleHaze that focused a South Asian authorities supporting entity with a Home windows backdoor known as GoReShell, which makes use of functionalities from the reverse_ssh instrument to ascertain reverse SSH connections to attacker-controlled hosts.
Using reverse_ssh is notable because it permits the attacker to ascertain an outbound connection to an endpoint underneath their management, successfully bypassing safety controls designed to stop suspicious inbound requests.
“The presence of reverse_ssh mustn’t, by itself, be handled as proof of malicious exercise,” QUIRSO famous. “Together with unauthorized set up, surprising outbound connections or execution on a weak vCenter equipment, nevertheless, it’s a high-priority indicator requiring investigation.”
The disclosure comes as Defused Cyber stated it is observing a spike in scanning towards VMware vCenter that’s indicative of potential exploitation efforts focusing on CVE-2026-59309 (CVSS rating: 9.8).
“Our honeypots are logging elevated fingerprinting – reminiscent of model probes by way of POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO movement – coinciding with Broadcom’s VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8),” the cybersecurity firm stated.
Denis Szadkowski, COO and co-founder of QUIRSO GmbH, advised The Hacker Information that there’s not sufficient proof at this stage to correlate exploitation and scanning efforts utilizing CVE-2026-59309 with the intrusion set or the attacker infrastructure related to CVE-2026-59310.
“What we will say with a lot greater confidence is that the exercise we investigated represents a profitable compromise reasonably than merely exploitation makes an attempt, and the forensic proof strongly factors towards CVE-2026-59310 because the preliminary entry vector,” Szadkowski added.

