Find notable cyber news and cases, enriched with sources, timelines, and signals.

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that lets a network-access attacker execute arbitrary code. Active exploitation has now been observed shortly after Broadcom's late-July patch release, raising urgency for exposed vCenter servers. QUIRSO linked the activity to an intrusion chain that used path traversal and then reverse_ssh for persistence and outbound access.

Related Happenings

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave
H score46 First: 12.08.2026 12:01 Last: 12.08.2026 12:01 Sources 1

How related: Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaws. In all, there are as many as 361 unique victim IP addresses located across 47 countries.

About this happening: Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence....

CISA KEV remediation deadline for CVE-2026-22719

Public Sector Action
H score35 First: 04.03.2026 06:35 Last: 04.03.2026 06:35 Sources 1

About this happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign

Campaign
H score44 First: 17.02.2026 22:15 Last: 17.02.2026 22:15 Sources 1

About this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...

Latest development: 19.02.2026 17:30

CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.

CISA KEV remediation order for CVE-2025-22225

Public Sector Action
H score36 First: 04.02.2026 19:38 Last: 04.02.2026 19:38 Sources 1

About this happening: CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...

Timeline

  1. 12.08.2026 12:01 1 articles · 2h ago

    Compromised VMware vCenter systems contact attacker domains and establish reverse_ssh persistence

    Exploitation Observed

    Compromised Broadcom VMware vCenter systems first contacted attacker-controlled domains on August 3, and the intrusion chain moved from path traversal to a malicious cron job that used reverse_ssh to establish persistence and outbound SSH access.

    Show sources
  2. 12.08.2026 12:01 2 articles · 2h ago

    QUIRSO identifies active exploitation of CVE-2026-59310 in Broadcom VMware vCenter

    Initial Disclosure

    QUIRSO said threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal flaw in Broadcom VMware vCenter that can allow arbitrary code execution, and said the investigated activity was a successful compromise with CVE-2026-59310 as the likely initial access vector. The same reporting tied the campaign to up to 361 unique victim IP addresses across 47 countries and noted separate scanning and fingerprinting against VMware vCenter that may indicate CVE-2026-59309 exploitation.

    Show sources