A critical VMware vCenter directory traversal flaw, tracked as CVE-2026-59310, is being actively exploited to achieve unauthenticated remote code execution through the vCenter Syslog Server component. Broadcom disclosed the issue and released emergency patches, warning that any attacker with network access to a vulnerable system could run arbitrary code. No workaround was provided, leaving patching and exposure reduction as the primary defenses for affected vCenter deployments.
Incident responders at QUIRSO reported exploitation beginning shortly after disclosure and said attackers are deploying the open-source reverse_ssh tool to establish outbound command-and-control channels and maintain persistence. The firm counted 361 victim IP addresses across 47 countries within days, while administrators on r/sysadmin amplified warnings to patch immediately and noted that internet-exposed or poorly isolated vCenter instances remain especially vulnerable. QUIRSO said the activity may be linked to an APT actor, though it has not publicly released supporting evidence and is coordinating indicators with law enforcement.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
CISA added Broadcom VMware vCenter flaw CVE-2026-59310 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The agency directed federal civilian executive branch agencies to apply mitigations under BOD 26-04 and follow Broadcom's remediation guidance.
By August 7, QUIRSO had identified 361 victim IP addresses across 47 countries in the VMware vCenter exploitation campaign. More than half of the identified victims were located in Germany, the United States, Turkey, Iran, and France.
QUIRSO reported that the number of victim IP addresses linked to exploitation of CVE-2026-59310 had reached 343. This showed rapid expansion of the campaign against vulnerable VMware vCenter systems.
QUIRSO reported seeing 151 new victim IP addresses tied to the VMware vCenter exploitation campaign. The observed compromises were associated with attacker use of reverse SSH access channels.
QUIRSO observed compromised VMware vCenter systems connecting to attacker-controlled infrastructure, indicating exploitation had begun. The activity involved deployment of the open-source reverse_ssh tool for persistence and remote access.
Broadcom disclosed the critical VMware vCenter Syslog Server directory traversal vulnerability CVE-2026-59310 and warned that an unauthenticated attacker with network access could execute arbitrary code. It released emergency updates for affected vCenter versions and provided no workarounds or mitigations.
A post on r/sysadmin warned administrators that the critical VMware vCenter flaw CVE-2026-59310 was under active exploitation, linking to BleepingComputer coverage and Broadcom's advisory. The discussion urged immediate patching and repeated reports of 361 compromised IPs across 47 countries.
QUIRSO detailed how attackers exploited CVE-2026-59310 by writing malformed cron files under /etc/cron.d to execute commands as root, then established persistence through services, SSH key insertion, a JSP web shell, and creation of vSphere administrator accounts. The investigation also described follow-on movement to ESXi hosts, where attackers staged a Babuk-derived ransomware payload and helper scripts via the datastore browser.
QUIRSO-linked incident response findings said the VMware vCenter exploitation campaign culminated in deployment of Babuk-derived ransomware on ESXi hypervisors. The malware encrypted virtual machine-related files and appended the .babyk extension, marking an escalation from initial compromise and persistence to destructive or financially motivated impact.
QUIRSO assessed with moderate confidence that exploitation of CVE-2026-59310 was conducted by a Chinese-speaking threat actor likely operating in the UTC+08:00 time zone. The attribution was based on Chinese-language artifacts, tooling, research reuse, victimology excluding mainland China, and working-hour patterns.
QUIRSO said the global exploitation campaign targeting CVE-2026-59310 appeared to be the work of a single suspected advanced persistent threat actor. The firm also published a YARA rule to help defenders identify reverse_ssh builds used for post-exploitation persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
14 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcereddit.com
Open sourcebleepingcomputer.com
Open sourcecve.org
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.