VMware security advisories prompted national CERT notifications covering four vulnerabilities — CVE-2026-41703, CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310 — affecting a wide range of products, including VMware Cloud Foundation, VMware vSphere Foundation, VMware ESXi, VMware vCenter, VMware Workstation, VMware Fusion, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. South Korea’s KISA published a remediation matrix showing that the issues span both datacenter and endpoint virtualization platforms.
The published guidance maps each flaw to fixed builds, update releases, and vendor knowledge base patches, including ESXi80U3i-25205845, ESXi80U3k-25595708, vCenter 8.0 U3k, vCenter 8.0 U2f, KB449886, and KB88287. Separate CERT-PY notices also warned about VMware product vulnerabilities, reinforcing the need for organizations running VMware infrastructure to identify affected versions and apply the corresponding updates across exposed environments.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
KISA published a VMware security update advisory mapping affected products to remediated versions for CVE-2026-41703, CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310. The advisory lists fixes across VMware Cloud Foundation, vSphere Foundation, ESXi, vCenter, Workstation, Fusion, and Telco Cloud products.
Broadcom revised its advisory for CVE-2026-59310 on August 3 to add VMware vCenter 8.0 U2f express patches. The update expanded the listed fixed releases after the company had initially said on July 29 that it had not observed exploitation.
QUIRSO reported successful compromises of VMware vCenter appliances via CVE-2026-59310, observing path traversal activity followed by deployment of a malicious cron job and reverse_ssh for persistence and outbound connectivity. The firm said compromised systems first contacted attacker-controlled domains on August 3 and identified up to 361 victim IPs across 47 countries.
CERT-PY published a subsequent advisory, also titled "Vulnerabilidades en productos VMware." The provided reference does not expose further technical details, so only the publication of the advisory can be anchored.
After Broadcom disclosed VMSA-2026-0006 on July 29, DefusedCyber observed increased fingerprinting activity against exposed VMware vCenter instances, including requests to /sdk/ using RetrieveServiceContent and probes of /websso/. The activity was described as reconnaissance for vulnerable targets rather than confirmed exploitation.
CERT-PY published an advisory titled "Vulnerabilidades en productos VMware" covering VMware product vulnerabilities. The provided reference does not include additional event details beyond the existence of the advisory.
Quirso released a generic YARA rule to help identify reverse_ssh builds used by attackers after compromising VMware vCenter servers via CVE-2026-59310. The firm also advised organizations to investigate detections by checking for unauthorized installations, unexpected outbound connections, and suspicious execution activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecsirt.sk
Open sourcesecurityweek.com
Open sourceheise.de
Open sourcemedium.com
Open sourceboho.or.kr
Open sourcecert.gov.py
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.