Find notable cyber news and cases, enriched with sources, timelines, and signals.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave
First reported
Last updated
Happening score
H score 48
3 unique sources, 5 articles

Summary

Hide ▲

Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code execution on vulnerable appliances. QUIRSO said the activity began five calendar days after public disclosure, with 361 unique victim IP addresses across 47 countries and the largest clusters in Germany, the U.S., Turkey, Iran, and France. The intrusion chain included cron-abused payloads, a linuxFile WebSocket backdoor, and reverse_ssh for persistence and outbound access. The campaign also touched CVE-2026-59309 on at least one system, and the observed outcome on one infected host included Babuk-derived ransomware that encrypted files with the .babyk extension.

Related Happenings

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability
H score47 First: 12.08.2026 12:01 Last: 12.08.2026 12:01 Sources 1

How related: The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.

About this happening: CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that allows arbitrary code execution. QUIRSO attributed active exploitation*...

Broadcom VMware Avi Load Balancer security update release

Security Patch Release
H score26 First: 14.07.2026 16:55 Last: 14.07.2026 16:55 Sources 1

About this happening: Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...

VMware Aria Operations command injection flaw (CVE-2026-22719, exploited)

Vulnerability
H score32 First: 04.03.2026 01:40 Last: 04.03.2026 01:40 Sources 1

About this happening: CISA added CVE-2026-22719 in VMware Aria Operations to its KEV catalog, indicating the command injection flaw is being exploited and could lead to remote cod...

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign

Campaign
H score44 First: 17.02.2026 22:15 Last: 17.02.2026 22:15 Sources 1

About this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...

Latest development: 19.02.2026 17:30

CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.

Timeline

  1. 12.08.2026 12:01 6 articles · 13d ago

    Broadcom VMware vCenter compromise establishes reverse_ssh persistence

    Exploitation Observed

    Compromised Broadcom VMware vCenter systems first contacted attacker domains on August 3, and the intrusion chain showed path traversal consistent with CVE-2026-59310 followed by a malicious cron job that used reverse_ssh to establish persistence and outbound access to attacker-controlled infrastructure.

    Show sources
  2. 12.08.2026 12:01 1 articles · 13d ago

    QUIRSO reports active exploitation of CVE-2026-59310 in Broadcom VMware vCenter

    Initial Disclosure

    QUIRSO said it discovered the activity during an incident response engagement and reported active exploitation of CVE-2026-59310 in Broadcom VMware vCenter, noting that the campaign likely began after disclosure and that as many as 361 unique victim IP addresses were identified across 47 countries.

    Show sources