Find notable cyber news and cases, enriched with sources, timelines, and signals.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence. The wave has reached 361 unique victim IP addresses across 47 countries, with attackers using path traversal followed by a malicious cron job and reverse_ssh to hold access. Activity began on August 3, shortly after disclosure, indicating rapid post-patch abuse of vulnerable appliances.

Related Happenings

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability
H score47 First: 12.08.2026 12:01 Last: 12.08.2026 12:01 Sources 1

How related: The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code.

About this happening: CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitat...

Broadcom VMware Avi Load Balancer security update release

Security Patch Release
H score26 First: 14.07.2026 16:55 Last: 14.07.2026 16:55 Sources 1

About this happening: Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...

VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)

Vulnerability
H score32 First: 04.03.2026 01:40 Last: 04.03.2026 01:40 Sources 1

About this happening: CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

VMware ESXi arbitrary-write sandbox escape (CVE-2025-22225)

Vulnerability
H score41 First: 04.02.2026 19:38 Last: 04.02.2026 19:38 Sources 1

About this happening: CVE-2025-22225 is now confirmed in ransomware campaigns, making the VMware ESXi sandbox-escape flaw an active risk for exposed virtualization hosts. Broadcom patch...

Timeline

  1. 12.08.2026 12:01 2 articles · 2h ago

    Broadcom VMware vCenter compromise establishes reverse_ssh persistence

    Exploitation Observed

    Compromised Broadcom VMware vCenter systems first contacted attacker domains on August 3, and the intrusion chain showed path traversal consistent with CVE-2026-59310 followed by a malicious cron job that used reverse_ssh to establish persistence and outbound access to attacker-controlled infrastructure.

    Show sources
  2. 12.08.2026 12:01 1 articles · 2h ago

    QUIRSO reports active exploitation of CVE-2026-59310 in Broadcom VMware vCenter

    Initial Disclosure

    QUIRSO said it discovered the activity during an incident response engagement and reported active exploitation of CVE-2026-59310 in Broadcom VMware vCenter, noting that the campaign likely began after disclosure and that as many as 361 unique victim IP addresses were identified across 47 countries.

    Show sources