Find notable cyber news and cases, enriched with sources, timelines, and signals.

VMware vCenter actively exploited directory-traversal RCE (CVE-2026-59310)

Vulnerability
First reported
Last updated
Happening score
H score 47
3 unique sources, 4 articles

Summary

Hide ▲

CVE-2026-59310 is a critical 9.8 directory-traversal flaw in Broadcom VMware vCenter that allows arbitrary code execution. QUIRSO attributed active exploitation of the newly patched vulnerability to a suspected China-nexus APT, with activity beginning five days after public disclosure and affecting 361 unique victim IP addresses across 47 countries. The intrusion used cron-abused payloads, the linuxFile WebSocket backdoor, and masqueraded VMware-style account creation to gain root execution on vCenter systems. The same reporting also observed activity consistent with CVE-2026-59309 on one compromised appliance, and the campaign ended with Babuk-derived ransomware that encrypts files with the .babyk extension.

Related Happenings

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave
H score48 First: 12.08.2026 12:01 Last: 12.08.2026 12:01 Sources 1

How related: A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems.

About this happening: Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code executio...

CISA KEV remediation deadline for CVE-2026-22719

Public Sector Action
H score35 First: 04.03.2026 06:35 Last: 04.03.2026 06:35 Sources 1

About this happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-22719 to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilia...

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

UNC6201 Dell RecoverPoint for Virtual Machines zero-day campaign

Campaign
H score44 First: 17.02.2026 22:15 Last: 17.02.2026 22:15 Sources 1

About this happening: The UNC6201 campaign has been exploiting a Dell zero-day since mid-2024, creating a sustained risk of unauthorized access and stealthy movement across victims' virtual...

Latest development: 19.02.2026 17:30

CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure affected Dell RecoverPoint systems by Saturday, February 21, after Mandiant and Google Threat Intelligence Group (GTIG) said UNC6201 had exploited the flaw since at least mid-2024.

CISA KEV remediation order for CVE-2025-22225

Public Sector Action
H score36 First: 04.02.2026 19:38 Last: 04.02.2026 19:38 Sources 1

About this happening: CISA added CVE-2025-22225 to the Known Exploited Vulnerabilities (KEV) catalog and ordered federal agencies to secure affected systems by March 25, 2025. The d...

Timeline

  1. 12.08.2026 12:01 4 articles · 13d ago

    Compromised VMware vCenter systems contact attacker domains and establish reverse_ssh persistence

    Exploitation Observed

    Compromised Broadcom VMware vCenter systems first contacted attacker-controlled domains on August 3, and the intrusion chain moved from path traversal to a malicious cron job that used reverse_ssh to establish persistence and outbound SSH access.

    Show sources
  2. 12.08.2026 12:01 2 articles · 13d ago

    QUIRSO identifies active exploitation of CVE-2026-59310 in Broadcom VMware vCenter

    Initial Disclosure

    QUIRSO said threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal flaw in Broadcom VMware vCenter that can allow arbitrary code execution, and said the investigated activity was a successful compromise with CVE-2026-59310 as the likely initial access vector. The same reporting tied the campaign to up to 361 unique victim IP addresses across 47 countries and noted separate scanning and fingerprinting against VMware vCenter that may indicate CVE-2026-59309 exploitation.

    Show sources