Home/TECH/MIDDLE_EAST/Article
TrendingTECH

Attackers exploit critical VMware vCenter vulnerability for remote access

Cybersecurity experts warn of a critical flaw, CVE-2026-59310, in Broadcom VMware vCenter being actively exploited. 361 victim IPs found across 47 countries. Exploitation began soon after public disclosure, raising fears of advanced persistent threat actors at work.

BRIC Team
BRIC Team
Aug 12, 2026 · 2 min read · 25 views
Attackers exploit critical VMware vCenter vulnerability for remote access

Key Takeaways

  • Critical vulnerability in Broadcom VMware vCenter is being actively exploited
  • Severity score of 9.8 highlights significant security risks
  • Organizations urged to apply patches and monitor for unauthorized access
  • Exploitation linked to advanced persistent threat actors, raising alarm among

Cybersecurity experts have raised alarms over a critical vulnerability in Broadcom VMware vCenter,which is currently being exploited by threat actors . flaw, identified as CVE-2026-59310, has a CVSS score of 9.8,indicating its severity. This directory-traversal vulnerability allows attackers with network access to execute arbitrary code on affected systems.

Following the public disclosure of the vulnerability by Broadcom in late July,malicious activity began to surface. The German cybersecurity firm QUIRSO reported that compromised systems first connected to attacker-controlled domains on August 3,just five days after the flaw was made public. firm identified 361 unique victim IP addresses across 47 countries, with the highest concentrations in Germany, the United States,Turkey, Iran, and France.

QUIRSO's findings suggest that while the attackers may have had prior knowledge of the vulnerability,the timing of the exploitation closely correlates with the public disclosure. This indicates that the disclosure likely served as a catalyst for the exploitation campaign. The exact identity of the attackers remains unclear, but the activity is suspected to be linked to advanced persistent threat (APT) actor.

VMware products have previously been targeted by various threat groups, particularly those associated with China. Notably,the group known as UNC5174 has exploited vulnerabilities in VMware Tools and vCenter in espionage operations . In April 2025, another cybersecurity firm, SentinelOne, revealed a threat cluster named PurpleHaze, which targeted a South Asian government entity using a Windows backdoor called GoReShell. This backdoor utilized functionalities from the reversessh tool,enabling attackers to establish reverse SSH connections to their own servers .

The use of reversessh is particularly concerning, as it allows attackers to circumvent security measures designed to block unauthorized inbound requests. QUIRSO cautioned that while the presence of reversessh alone does not confirm malicious intent, its combination with unauthorized installations or unexpected outbound connections on a vulnerable vCenter appliance is a significant indicator that warrants investigation.

As the situation unfolds,another cybersecurity firm, Defused Cyber,has reported surge in scanning activities targeting VMware vCenter, suggesting potential exploitation efforts related to another vulnerability, CVE-2026-59309, which also carries a CVSS score of 9.8. Defused Cyber noted increased fingerprinting activities,including version probes and SAML SSO flow, coinciding with Broadcom’s advisory on this vulnerability.

Denis Szadkowski,COO and co-founder of QUIRSO GmbH,emphasized the need for caution. He stated that while there is insufficient evidence to directly link scanning activities associated with CVE-2026-59309 to the exploitation of CVE-2026-59310,the forensic evidence strongly suggests that the latter was the initial access vector for the successful compromises observed.

As organizations continue to assess their cybersecurity posture, the exploitation of these vulnerabilities serves as stark reminder of the persistent threats posed by sophisticated cyber actors. Companies using VMware products are urged to apply latest patches and monitor their systems for any signs of unauthorized access .

#technology

Share this article

Related Articles

Twitch users criticize platform for allowing Amazon to use content for AI training

Twitch users criticize platform for allowing Amazon to use content for AI training

Twitch users are furious over Amazon using their content for AI training, with default settings allowing this without clear consent. Twitch admitted few would opt in voluntarily, sparking criticism over data rights and transparency.

Utkarsh Aggrawal

Aug 13, 202621 views
Formula E secures streaming deal with Disney+ and ESPN+ for 2026-27 season

Formula E secures streaming deal with Disney+ and ESPN+ for 2026-27 season

Formula E inks a multiyear deal with Disney+ and ESPN+ to broadcast in 144 countries starting December. This aligns with the GEN4 car's debut, boosting the sport's visibility and audience engagement.

Daniel Brown

Aug 13, 202625 views
Natarajan Chandrasekaran reshapes Tata Group with tech-focused strategy since 2017

Natarajan Chandrasekaran reshapes Tata Group with tech-focused strategy since 2017

Natarajan Chandrasekaran will step down as Tata Sons chairman in February 2027 after leading major tech investments. His departure follows internal shifts at Tata Trusts and uncertainty over term extension, leaving questions about Tata Group's future direction.

Shagun Pandey

Aug 13, 202623 views
Nine new cars launching in India from August 14 to 26, including Mahindra and MG

Nine new cars launching in India from August 14 to 26, including Mahindra and MG

From August 14 to August 26, nine new vehicles from brands like Mahindra and MG will launch in India. This surge in new models could heavily influence consumer choices in the competitive SUV and luxury car market.

Daniel Brown

Aug 13, 202622 views
Mahindra reveals first look at Scorpio-N pick-up ahead of August 14 launch

Mahindra reveals first look at Scorpio-N pick-up ahead of August 14 launch

Mahindra set to launch the Scorpio-N pick-up truck on August 14, 2026, entering lifestyle segment. Competing with Isuzu V-Cross and Toyota Hilux, it showcases major design and interior enhancements.

Rahul Sharma

Aug 12, 202619 views
Nvidia secures $500 billion from Wall Street banks for AI infrastructure

Nvidia secures $500 billion from Wall Street banks for AI infrastructure

Nvidia secured $500 billion from major investors like Apollo and KKR to boost AI infrastructure. Funds will build new data centers and AI chip factories, as CEO Jensen Huang calls these 'AI factories,' marking Nvidia's move beyond chip-making.

Daniel Brown

Aug 11, 202651 views