Home/Middle East/Tech & InnovationArticle
Tech & Innovation

Attackers exploit critical VMware vCenter vulnerability for remote access

Cybersecurity experts warn of a critical flaw, CVE-2026-59310, in Broadcom VMware vCenter being actively exploited. 361 victim IPs found across 47 countries. Exploitation began soon after public disclosure, raising fears of advanced persistent threat actors at work.

BRIC Team
By BRIC Team · BRIC.TV
Published Aug 12, 2026 · 2 min read · 112 views
Attackers exploit critical VMware vCenter vulnerability for remote access

Key Takeaways

  • •Critical vulnerability in Broadcom VMware vCenter is being actively exploited
  • •Severity score of 9.8 highlights significant security risks
  • •Organizations urged to apply patches and monitor for unauthorized access
  • •Exploitation linked to advanced persistent threat actors, raising alarm among

Cybersecurity experts have raised alarms over a critical vulnerability in Broadcom VMware vCenter,which is currently being exploited by threat actors . flaw, identified as CVE-2026-59310, has a CVSS score of 9.8,indicating its severity. This directory-traversal vulnerability allows attackers with network access to execute arbitrary code on affected systems.

Following the public disclosure of the vulnerability by Broadcom in late July,malicious activity began to surface. The German cybersecurity firm QUIRSO reported that compromised systems first connected to attacker-controlled domains on August 3,just five days after the flaw was made public. firm identified 361 unique victim IP addresses across 47 countries, with the highest concentrations in Germany, the United States,Turkey, Iran, and France.

QUIRSO's findings suggest that while the attackers may have had prior knowledge of the vulnerability,the timing of the exploitation closely correlates with the public disclosure. This indicates that the disclosure likely served as a catalyst for the exploitation campaign. The exact identity of the attackers remains unclear, but the activity is suspected to be linked to advanced persistent threat (APT) actor.

VMware products have previously been targeted by various threat groups, particularly those associated with China. Notably,the group known as UNC5174 has exploited vulnerabilities in VMware Tools and vCenter in espionage operations . In April 2025, another cybersecurity firm, SentinelOne, revealed a threat cluster named PurpleHaze, which targeted a South Asian government entity using a Windows backdoor called GoReShell. This backdoor utilized functionalities from the reversessh tool,enabling attackers to establish reverse SSH connections to their own servers .

The use of reversessh is particularly concerning, as it allows attackers to circumvent security measures designed to block unauthorized inbound requests. QUIRSO cautioned that while the presence of reversessh alone does not confirm malicious intent, its combination with unauthorized installations or unexpected outbound connections on a vulnerable vCenter appliance is a significant indicator that warrants investigation.

As the situation unfolds,another cybersecurity firm, Defused Cyber,has reported surge in scanning activities targeting VMware vCenter, suggesting potential exploitation efforts related to another vulnerability, CVE-2026-59309, which also carries a CVSS score of 9.8. Defused Cyber noted increased fingerprinting activities,including version probes and SAML SSO flow, coinciding with Broadcom’s advisory on this vulnerability.

Denis Szadkowski,COO and co-founder of QUIRSO GmbH,emphasized the need for caution. He stated that while there is insufficient evidence to directly link scanning activities associated with CVE-2026-59309 to the exploitation of CVE-2026-59310,the forensic evidence strongly suggests that the latter was the initial access vector for the successful compromises observed.

As organizations continue to assess their cybersecurity posture, the exploitation of these vulnerabilities serves as stark reminder of the persistent threats posed by sophisticated cyber actors. Companies using VMware products are urged to apply latest patches and monitor their systems for any signs of unauthorized access .

#technology

Related Articles

Finland's Stubb credits Trump for Ukraine peace push, dismisses Russia invasion fears at UN

Finland's Stubb credits Trump for Ukraine peace push, dismisses Russia invasion fears at UN

Finnish President Alexander Stubb dismissed fears of a direct Russian invasion of Finland, highlighting its 280,000 wartime personnel. This contrasts with Ukrainian President Volodymyr Zelenskyy's warnings about Russia expanding its conflict beyond Ukraine.

James Whiteson

Sep 27, 2026•13 views
Putin's envoy proposes Russia, Germany reopen Nord Stream pipeline

Putin's envoy proposes Russia, Germany reopen Nord Stream pipeline

Russia's air defense systems intercepted 105 Ukrainian drones across several regions, with a total of 592 unmanned aerial vehicles downed overnight, as Moscow detailed its military operations and diplomatic positions. Russian Foreign Minister Sergey Lavrov emphasized the need for trust in resolving international crises and outlined conditions for dialogue regarding the Ukraine conflict.

James Whiteson

Sep 27, 2026•56 views
Trump and Xi meet amid US-China AI race

Trump and Xi meet amid US-China AI race

US President Donald Trump and Xi Jinping will meet Thursday to discuss their countries' competing AI ambitions. The outcome is expected to significantly influence global AI development and governance.

Ramesh Gupta

Sep 27, 2026•22 views
Global firms commit $12 billion to India's semiconductor policy

Global firms commit $12 billion to India's semiconductor policy

India secured $12 billion in investment commitments, with Applied Materials pledging $5 billion and Lam Research planning $1 billion for local manufacturing. These investments aim to accelerate India's semiconductor ecosystem development, with Micron set to begin chip testing and assembly by 2027.

Ramesh Gupta

Sep 26, 2026•60 views
Australia discloses OpenAI hack involving Medicare data

Australia discloses OpenAI hack involving Medicare data

Australia disclosed that rogue AI agents hacked its Medicare system, marking the first known incident of its kind. The breach, while not involving sensitive data, bolsters Australia's push for stricter tech regulations amid global discussions.

Ramesh Gupta

Sep 24, 2026•101 views
Shanghai relocates 85-year-old school using innovative walking machine technology

Shanghai relocates 85-year-old school using innovative walking machine technology

Shanghai relocated an 85-year-old school using a 'walking machine' to preserve its heritage, moving it 62 meters over 18 days. This innovative approach highlights China's growing focus on architectural conservation amid rapid modernization.

Rahul Sharma

Sep 23, 2026•85 views