VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitation has now been observed shortly after Broadcom's late-July patch release, raising urgency for exposed vCenter servers. QUIRSO linked the activity to an intrusion chain that used path traversal and then reverse_ssh for persistence and outbound access.
Related Happenings
Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation Wave
H score46
First: 12.08.2026 12:01
Last: 12.08.2026 12:01
Sources 1
How related:
Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaws. In all, there are as many as 361 unique victim IP addresses located across 47 countries.
About this happening:
Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence....
Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation WaveHow related: Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaws. In all, there are as many as 361 unique victim IP addresses located across 47 countries.
About this happening: Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence....
CISA KEV remediation deadline for CVE-2026-22719
Public Sector Action
H score35
First: 04.03.2026 06:35
Last: 04.03.2026 06:35
Sources 1
About this happening:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...
CISA KEV remediation deadline for CVE-2026-22719
Public Sector ActionAbout this happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
Campaign
H score44
First: 17.02.2026 22:15
Last: 17.02.2026 22:15
Sources 1
About this happening:
The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
CampaignAbout this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
Latest development: 19.02.2026 17:30
CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.
CISA KEV remediation order for CVE-2025-22225
Public Sector Action
H score36
First: 04.02.2026 19:38
Last: 04.02.2026 19:38
Sources 1
About this happening:
CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...
CISA KEV remediation order for CVE-2025-22225
Public Sector ActionAbout this happening: CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...
Timeline
-
12.08.2026 12:01 1 articles · 2h ago
Compromised VMware vCenter systems contact attacker domains and establish reverse_ssh persistence
Exploitation ObservedCompromised Broadcom VMware vCenter systems first contacted attacker-controlled domains on August 3, and the intrusion chain moved from path traversal to a malicious cron job that used reverse_ssh to establish persistence and outbound SSH access.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
-
12.08.2026 12:01 2 articles · 2h ago
QUIRSO identifies active exploitation of CVE-2026-59310 in Broadcom VMware vCenter
Initial DisclosureQUIRSO said threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal flaw in Broadcom VMware vCenter that can allow arbitrary code execution, and said the investigated activity was a successful compromise with CVE-2026-59310 as the likely initial access vector. The same reporting tied the campaign to up to 361 unique victim IP addresses across 47 countries and noted separate scanning and fingerprinting against VMware vCenter that may indicate CVE-2026-59309 exploitation.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01