Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
- ID
- 13451
- Status
- summarized
- Published
- 12 Aug 2026, 5:01 PM
- Fetched
- 12 Aug 2026, 7:28 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 12 Aug 2026, 7:29 PM
- Tags
- Audience
- developerssaas_founders
What happened
Attackers are actively exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in Broadcom VMware vCenter, with 361 victim IPs across 47 countries as of August 2026. Patches were released by Broadcom in late July 2026, and exploitation began within days of disclosure, using reverse_ssh via cron jobs for persistent remote access. QUIRSO attributes the campaign to a suspected APT actor.
Why it matters
If your team runs VMware vCenter and has not applied Broadcom's late-July 2026 patch, patch now — the exploit chain is trivial enough that 361 hosts were compromised within days of disclosure. The reverse_ssh persistence technique bypasses inbound firewall rules, so compromised hosts may not show obvious inbound connection alerts.
Discussion angle
How quickly after patch release do you verify critical infrastructure updates are applied, and do you have detection for reverse_ssh or similar outbound-persistence tooling in your environment?