Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation Wave
Summary
Hide ▲
Show ▼
Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code execution on vulnerable appliances. QUIRSO said the activity began five calendar days after public disclosure, with 361 unique victim IP addresses across 47 countries and the largest clusters in Germany, the U.S., Turkey, Iran, and France. The intrusion chain included cron-abused payloads, a linuxFile WebSocket backdoor, and reverse_ssh for persistence and outbound access. The campaign also touched CVE-2026-59309 on at least one system, and the observed outcome on one infected host included Babuk-derived ransomware that encrypted files with the .babyk extension.
Related Happenings
VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)
Vulnerability
H score47
First: 12.08.2026 12:01
Last: 12.08.2026 12:01
Sources 1
How related:
The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.
About this happening:
CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that allows arbitrary code execution. QUIRSO attributed active exploitation*...
VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)
VulnerabilityHow related: The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.
About this happening: CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that allows arbitrary code execution. QUIRSO attributed active exploitation*...
Broadcom VMware Avi Load Balancer security update release
Security Patch Release
H score26
First: 14.07.2026 16:55
Last: 14.07.2026 16:55
Sources 1
About this happening:
Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
Broadcom VMware Avi Load Balancer security update release
Security Patch ReleaseAbout this happening: Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)
Vulnerability
H score32
First: 04.03.2026 01:40
Last: 04.03.2026 01:40
Sources 1
About this happening:
CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...
VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)
VulnerabilityAbout this happening: CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
Campaign
H score44
First: 17.02.2026 22:15
Last: 17.02.2026 22:15
Sources 1
About this happening:
The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign
CampaignAbout this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...
Latest development: 19.02.2026 17:30
CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.
Timeline
-
12.08.2026 12:01 6 articles · 13d ago
Broadcom VMware vCenter compromise establishes reverse_ssh persistence
Exploitation ObservedCompromised Broadcom VMware vCenter systems first contacted attacker domains on August 3, and the intrusion chain showed path traversal consistent with CVE-2026-59310 followed by a malicious cron job that used reverse_ssh to establish persistence and outbound access to attacker-controlled infrastructure.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01
- vCenter Flaw Exploited Just Five Days After Disclosure — www.infosecurity-magazine.com — 13.08.2026 17:00
- Critical VMware vCenter RCE flaw exploited for reverse SSH access — www.bleepingcomputer.com — 13.08.2026 19:40
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware — thehackernews.com — 17.08.2026 10:36
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation — thehackernews.com — 19.08.2026 14:01
-
12.08.2026 12:01 1 articles · 13d ago
QUIRSO reports active exploitation of CVE-2026-59310 in Broadcom VMware vCenter
Initial DisclosureQUIRSO said it discovered the activity during an incident response engagement and reported active exploitation of CVE-2026-59310 in Broadcom VMware vCenter, noting that the campaign likely began after disclosure and that as many as 361 unique victim IP addresses were identified across 47 countries.
Show sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com — 12.08.2026 12:01