Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation Wave
Summary
Hide ▲
Show ▼
Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence. The wave has reached 361 unique victim IP addresses across 47 countries, with attackers using path traversal followed by a malicious cron job and reverse_ssh to hold access. Activity began on August 3, shortly after disclosure, indicating rapid post-patch abuse of vulnerable appliances.
Related Happenings
VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)
Vulnerability
H score47
First: 12.08.2026 12:01
Last: 12.08.2026 12:01
Sources 1
How related:
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code.
About this happening:
CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitat...
VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)
VulnerabilityHow related: The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code.
About this happening: CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitat...
Broadcom VMware Avi Load Balancer security update release
Security Patch Release
H score26
First: 14.07.2026 16:55
Last: 14.07.2026 16:55
Sources 1
About this happening:
Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
Broadcom VMware Avi Load Balancer security update release
Security Patch ReleaseAbout this happening: Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)
Vulnerability
H score32
First: 04.03.2026 01:40
Last: 04.03.2026 01:40
Sources 1
About this happening:
CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...
VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)
VulnerabilityAbout this happening: CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
VMware ESXi arbitrary-write sandbox escape (CVE-2025-22225)
Vulnerability
H score41
First: 04.02.2026 19:38
Last: 04.02.2026 19:38
Sources 1
About this happening:
CVE-2025-22225 is now confirmed in ransomware campaigns, making the VMware ESXi sandbox-escape flaw an active risk for exposed virtualization hosts. Broadcom patch...
VMware ESXi arbitrary-write sandbox escape (CVE-2025-22225)
VulnerabilityAbout this happening: CVE-2025-22225 is now confirmed in ransomware campaigns, making the VMware ESXi sandbox-escape flaw an active risk for exposed virtualization hosts. Broadcom patch...
Timeline
-
12.08.2026 12:01 2 articles · 2h ago
Broadcom VMware vCenter compromise establishes reverse_ssh persistence
Exploitation ObservedCompromised Broadcom VMware vCenter systems first contacted attacker domains on August 3, and the intrusion chain showed path traversal consistent with CVE-2026-59310 followed by a malicious cron job that used reverse_ssh to establish persistence and outbound access to attacker-controlled infrastructure.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
-
12.08.2026 12:01 1 articles · 2h ago
QUIRSO reports active exploitation of CVE-2026-59310 in Broadcom VMware vCenter
Initial DisclosureQUIRSO said it discovered the activity during an incident response engagement and reported active exploitation of CVE-2026-59310 in Broadcom VMware vCenter, noting that the campaign likely began after disclosure and that as many as 361 unique victim IP addresses were identified across 47 countries.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01