Active exploitation of VMware vCenter CVE-2026-59310 reaches 361 IPs

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter Server with a CVSS score of 9.8. QUIRSO identified 361 unique victim IP addresses in 47 countries in an incident-response investigation, with the highest concentrations in Germany, the United States, Turkey, Iran and France.
Broadcom released patches for the flaw late last month. QUIRSO observed compromised systems contacting attacker domains from August 3, five days after the public disclosure of the vulnerabilities. The evidence examined by the German cybersecurity company indicates successful compromises, rather than attempted exploitation alone.
Path traversal followed by persistent remote access
CVE-2026-59310 can be used by a malicious actor with network access to a VMware vCenter Server to execute arbitrary code. In the incidents investigated by QUIRSO, path-traversal activity consistent with the vulnerability was followed by installation of a malicious cron job.
The cron job deployed reverse_ssh, an open-source tool for establishing SSH connections to infrastructure controlled by an attacker. This enables an outbound connection from the compromised appliance, potentially bypassing controls designed to block suspicious inbound requests.
QUIRSO cautioned that reverse_ssh alone is not proof of malicious activity. Its presence becomes a high-priority indicator when it is installed without authorisation, generates unexpected outbound connections, or runs on a vulnerable vCenter appliance. The actor behind the campaign has not been identified, although QUIRSO believes the activity may involve a suspected advanced persistent threat actor.
Related scanning requires separate assessment
Defused Cyber has also reported increased scanning of VMware vCenter systems associated with CVE-2026-59309, another 9.8-rated issue referenced in Broadcom VMSA-2026-0006. Its honeypots recorded version probes through POST /sdk/ RetrieveServiceContent requests and activity traversing the /websso SAML single sign-on flow.
Denis Szadkowski, COO and co-founder of QUIRSO, said there is not enough evidence to link the CVE-2026-59309 scanning to the intrusion set or infrastructure tied to CVE-2026-59310. For the investigated compromises, forensic evidence points much more strongly to CVE-2026-59310 as the initial access vector.
VMware appliances have also featured in espionage activity attributed to Chinese threat actors, including UNC5174, which has exploited flaws affecting VMware Tools and VMware vCenter. The risk fits the wider pattern of rapidly operationalised enterprise vulnerabilities described in rapidly operationalised enterprise vulnerabilities, where defenders need to distinguish broad scanning from confirmed compromise while acting quickly on both.
Actions for vCenter operators
Organizations should apply Broadcom’s available patches, review internet and network exposure of vCenter appliances, and investigate signs of path traversal, unauthorised cron entries and reverse_ssh execution. Monitoring unexpected outbound connections from vCenter systems can help security teams identify persistence after an intrusion. The immediate business implication is that patch status and post-patch compromise checks must be treated as separate operational tasks for exposed vCenter environments.

