Ethical Hacking News
VMware vCenter Vulnerability Exploitation: A Persistent Threat Vector for Attackers
The recent discovery of CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom's VMware vCenter server, has sparked widespread concern among cybersecurity experts. This article delves into the intricacies of this vulnerability and its implications for enterprise security. With threat actors exploiting this vulnerability on a large scale, organizations are urged to take immediate action to patch their systems and strengthen their defenses.
The CVE-2026-59310 vulnerability in Broadcom's VMware vCenter server has been exploited by threat actors, with 361 unique victim IP addresses located across 47 countries.A suspected advanced persistent threat (APT) actor is believed to be behind the exploitation campaign, using tools such as reverse_ssh to establish persistence on compromised systems.The use of reverse_ssh alone should not be considered proof of malicious activity, but rather a high-priority indicator requiring investigation when combined with other suspicious activity.Timely patch management and vulnerability scanning are crucial for enterprise security, especially for VMware appliances that have been targeted by Chinese threat actors in the past.The discovery highlights the importance of staying vigilant and proactive in the face of emerging security threats, and organizations should prioritize incident response to mitigate the risk of exploitation.
The cybersecurity landscape has witnessed a recent surge in high-stakes exploitation campaigns, as threat actors continue to capitalize on newly discovered vulnerabilities in software systems. The latest attack vector to gain attention is the exploitation of CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom's VMware vCenter server. This article will delve into the intricacies of this vulnerability and its implications for enterprise security.
The discovery of CVE-2026-59310 was announced by German cybersecurity company QUIRSO, which stated that it discovered the activity following an incident response engagement. The attack chain exhibited path traversal activity consistent with the flaw, followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh, an open-source tool used for setting up SSH connections to threat actor-controlled infrastructure.
The compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaws. In all, there are as many as 361 unique victim IP addresses located across 47 countries. Most of them are located in Germany, the U.S., Turkey, Iran, and France.
While it is unclear who is behind the exploitation campaign, it is believed to be the work of a suspected advanced persistent threat (APT) actor. The use of reverse_ssh is notable as it allows the attacker to establish an outbound connection to an endpoint under their control, effectively bypassing security controls designed to prevent suspicious inbound requests.
The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity," QUIRSO noted. "In combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, however, it is a high-priority indicator requiring investigation."
The disclosure comes as Defused Cyber said it's observing a spike in scanning against VMware vCenter that is indicative of potential exploitation efforts targeting CVE-2026-59309 (CVSS score: 9.8). The cybersecurity company stated that their honeypots are logging increased fingerprinting – such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow – coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8).
Denis Szadkowski, COO and co-founder of QUIRSO GmbH, stated that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.
"What we can say with much higher confidence is that the activity we investigated represents a successful compromise rather than merely exploitation attempts, and the forensic evidence strongly points toward CVE-2026-59310 as the initial access vector," Szadkowski added.
The discovery of CVE-2026-59310 highlights the importance of timely patch management and vulnerability scanning for enterprise security. VMware appliances have been a lucrative target for Chinese threat actors like UNC5174, who have weaponized security flaws impacting VMware Tools and VMware vCenter in various espionage campaigns.
In April 2025, SentinelOne disclosed details of a threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
The use of reverse_ssh is notable as it allows the attacker to establish an outbound connection to an endpoint under their control, effectively bypassing security controls designed to prevent suspicious inbound requests. However, this should not be taken at face value; in combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, it is a high-priority indicator requiring investigation.
The recent surge in threat actors exploiting CVE-2026-59310 serves as a stark reminder of the importance of staying vigilant and proactive in the face of emerging security threats. As the cybersecurity landscape continues to evolve, it is crucial for organizations to prioritize vulnerability scanning, patch management, and incident response to mitigate the risk of exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/VMware-vCenter-Vulnerability-Exploitation-A-Persistent-Threat-Vector-for-Attackers-ehn.shtml
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
Published: Wed Aug 12 05:00:19 2026 by llama3.2 3B Q4_K_M