Cybersecurity experts have raised alarms over a critical vulnerability in Broadcom VMware vCenter,which is currently being exploited by threat actors . flaw, identified as CVE-2026-59310, has a CVSS score of 9.8,indicating its severity. This directory-traversal vulnerability allows attackers with network access to execute arbitrary code on affected systems.
Following the public disclosure of the vulnerability by Broadcom in late July,malicious activity began to surface. The German cybersecurity firm QUIRSO reported that compromised systems first connected to attacker-controlled domains on August 3,just five days after the flaw was made public. firm identified 361 unique victim IP addresses across 47 countries, with the highest concentrations in Germany, the United States,Turkey, Iran, and France.
QUIRSO's findings suggest that while the attackers may have had prior knowledge of the vulnerability,the timing of the exploitation closely correlates with the public disclosure. This indicates that the disclosure likely served as a catalyst for the exploitation campaign. The exact identity of the attackers remains unclear, but the activity is suspected to be linked to advanced persistent threat (APT) actor.
VMware products have previously been targeted by various threat groups, particularly those associated with China. Notably,the group known as UNC5174 has exploited vulnerabilities in VMware Tools and vCenter in espionage operations . In April 2025, another cybersecurity firm, SentinelOne, revealed a threat cluster named PurpleHaze, which targeted a South Asian government entity using a Windows backdoor called GoReShell. This backdoor utilized functionalities from the reversessh tool,enabling attackers to establish reverse SSH connections to their own servers .
The use of reversessh is particularly concerning, as it allows attackers to circumvent security measures designed to block unauthorized inbound requests. QUIRSO cautioned that while the presence of reversessh alone does not confirm malicious intent, its combination with unauthorized installations or unexpected outbound connections on a vulnerable vCenter appliance is a significant indicator that warrants investigation.
As the situation unfolds,another cybersecurity firm, Defused Cyber,has reported surge in scanning activities targeting VMware vCenter, suggesting potential exploitation efforts related to another vulnerability, CVE-2026-59309, which also carries a CVSS score of 9.8. Defused Cyber noted increased fingerprinting activities,including version probes and SAML SSO flow, coinciding with Broadcom’s advisory on this vulnerability.
Denis Szadkowski,COO and co-founder of QUIRSO GmbH,emphasized the need for caution. He stated that while there is insufficient evidence to directly link scanning activities associated with CVE-2026-59309 to the exploitation of CVE-2026-59310,the forensic evidence strongly suggests that the latter was the initial access vector for the successful compromises observed.
As organizations continue to assess their cybersecurity posture, the exploitation of these vulnerabilities serves as stark reminder of the persistent threats posed by sophisticated cyber actors. Companies using VMware products are urged to apply latest patches and monitor their systems for any signs of unauthorized access .







