Zero Day Room
Live
Vulnerabilities

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability, CVE-2026-59310, is a directory-traversal vulnerability in the VMware vCenter server that can be exploited to execute arbitrary code.

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

## Vulnerability Exploited by Threat Actors Threat actors have started to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter. The vulnerability, identified as CVE-2026-59310, is a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were released by Broadcom late last month. The German cybersecurity company QUIRSO discovered the activity following an incident response engagement. The attack chain exhibited path traversal activity consistent with the flaw, followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh, an open-source tool used for setting up SSH connections to threat actor-controlled infrastructure. ## Compromised Systems and Attack Chain Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaw. In all, there are as many as 361 unique victim IP addresses located across 47 countries. Most of them are located in Germany, the U.S., Turkey, Iran, and France. The attack chain is notable for its use of reverse_ssh, which allows the attacker to establish an outbound connection to an endpoint under their control, effectively bypassing security controls designed to prevent suspicious inbound requests. However, QUIRSO noted that the presence of reverse_ssh should not, by itself, be treated as proof of malicious activity. ## Potential Connection to APT Actor It's not clear who is behind the exploitation campaign, but it's believed to be the work of a suspected advanced persistent threat (APT) actor. The use of reverse_ssh is reminiscent of a previous campaign by Chinese threat actors, who have weaponized security flaws impacting VMware Tools and VMware vCenter in various espionage campaigns. ## Scanning Against VMware vCenter The disclosure comes as Defused Cyber said it's observing a spike in scanning against VMware vCenter that is indicative of potential exploitation efforts targeting CVE-2026-59309 (CVSS score: 9.8). However, Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310. ## Conclusion The exploitation of the VMware vCenter vulnerability highlights the importance of patching critical security flaws in a timely manner. Organizations should ensure that their systems are up-to-date with the latest patches and monitor for suspicious activity, such as unexpected outbound connections or execution on a vulnerable vCenter appliance.

Related coverage

More from Vulnerabilities