Home/Middle East/Tech & InnovationArticle
Tech & Innovation

Attackers exploit critical VMware vCenter vulnerability for remote access

Cybersecurity experts warn of a critical flaw, CVE-2026-59310, in Broadcom VMware vCenter being actively exploited. 361 victim IPs found across 47 countries. Exploitation began soon after public disclosure, raising fears of advanced persistent threat actors at work.

BRIC Team
By BRIC Team · BRIC.TV
Published Aug 12, 2026 · 2 min read · 101 views
Attackers exploit critical VMware vCenter vulnerability for remote access

Key Takeaways

  • Critical vulnerability in Broadcom VMware vCenter is being actively exploited
  • Severity score of 9.8 highlights significant security risks
  • Organizations urged to apply patches and monitor for unauthorized access
  • Exploitation linked to advanced persistent threat actors, raising alarm among

Cybersecurity experts have raised alarms over a critical vulnerability in Broadcom VMware vCenter,which is currently being exploited by threat actors . flaw, identified as CVE-2026-59310, has a CVSS score of 9.8,indicating its severity. This directory-traversal vulnerability allows attackers with network access to execute arbitrary code on affected systems.

Following the public disclosure of the vulnerability by Broadcom in late July,malicious activity began to surface. The German cybersecurity firm QUIRSO reported that compromised systems first connected to attacker-controlled domains on August 3,just five days after the flaw was made public. firm identified 361 unique victim IP addresses across 47 countries, with the highest concentrations in Germany, the United States,Turkey, Iran, and France.

QUIRSO's findings suggest that while the attackers may have had prior knowledge of the vulnerability,the timing of the exploitation closely correlates with the public disclosure. This indicates that the disclosure likely served as a catalyst for the exploitation campaign. The exact identity of the attackers remains unclear, but the activity is suspected to be linked to advanced persistent threat (APT) actor.

VMware products have previously been targeted by various threat groups, particularly those associated with China. Notably,the group known as UNC5174 has exploited vulnerabilities in VMware Tools and vCenter in espionage operations . In April 2025, another cybersecurity firm, SentinelOne, revealed a threat cluster named PurpleHaze, which targeted a South Asian government entity using a Windows backdoor called GoReShell. This backdoor utilized functionalities from the reversessh tool,enabling attackers to establish reverse SSH connections to their own servers .

The use of reversessh is particularly concerning, as it allows attackers to circumvent security measures designed to block unauthorized inbound requests. QUIRSO cautioned that while the presence of reversessh alone does not confirm malicious intent, its combination with unauthorized installations or unexpected outbound connections on a vulnerable vCenter appliance is a significant indicator that warrants investigation.

As the situation unfolds,another cybersecurity firm, Defused Cyber,has reported surge in scanning activities targeting VMware vCenter, suggesting potential exploitation efforts related to another vulnerability, CVE-2026-59309, which also carries a CVSS score of 9.8. Defused Cyber noted increased fingerprinting activities,including version probes and SAML SSO flow, coinciding with Broadcom’s advisory on this vulnerability.

Denis Szadkowski,COO and co-founder of QUIRSO GmbH,emphasized the need for caution. He stated that while there is insufficient evidence to directly link scanning activities associated with CVE-2026-59309 to the exploitation of CVE-2026-59310,the forensic evidence strongly suggests that the latter was the initial access vector for the successful compromises observed.

As organizations continue to assess their cybersecurity posture, the exploitation of these vulnerabilities serves as stark reminder of the persistent threats posed by sophisticated cyber actors. Companies using VMware products are urged to apply latest patches and monitor their systems for any signs of unauthorized access .

#technology

Related Articles

Oracle’s AI Cloud Revenue Jump Revives the Hardware-and-Data-Centre Trade

Oracle’s AI Cloud Revenue Jump Revives the Hardware-and-Data-Centre Trade

The market is rewarding AI infrastructure suppliers, but it is still asking whether the buildout can generate enough durable margin. Oracle reported 30% revenue growth to $19.3 billion in its first quarter. AI cloud demand helped the company beat expectations.

Shagun Pandey

Sep 12, 2026399 views
India Tests Blockchain and Digital Rupee Rails for Corporate Bond Settlement

India Tests Blockchain and Digital Rupee Rails for Corporate Bond Settlement

If the rails scale, India could make bond-market plumbing faster without asking investors to change the asset they already understand. India has launched a Demat 2.0 push using blockchain and the digital rupee for corporate bond settlement. The goal is to tokenise corporate bonds and streamline settlement.

Rahul Sharma

Sep 12, 2026268 views
Larry Ellison Scraps Planned Oracle Share Sale as AI Data-Centre Bets Face Scrutiny

Larry Ellison Scraps Planned Oracle Share Sale as AI Data-Centre Bets Face Scrutiny

The cancelled sale gives investors a signal that Oracle insiders may see more value in the AI infrastructure story than the market currently grants. Larry Ellison cancelled a planned sale of up to $7.5 billion in Oracle shares. Oracle has been investing heavily in AI data centres.

Rahul Sharma

Sep 12, 20261227 views
AI Governance Moves Into the BRICS Core Agenda as India Pitches Digital Public Infrastructure

AI Governance Moves Into the BRICS Core Agenda as India Pitches Digital Public Infrastructure

For businesses, the signal is that AI policy is becoming a trade and productivity issue, not just a technology debate. BRICS endorsed AI principles built around access, safety and trust. The declaration placed special emphasis on the needs of the Global South.

Ramesh Gupta

Sep 12, 20261081 views
UPI becomes India’s calling card as BRICS weighs linking payment rails

UPI becomes India’s calling card as BRICS weighs linking payment rails

India is using the BRICS summit to pitch its Unified Payments Interface as a template for cross-border settlement, with New Delhi proposing links between member central bank digital currencies. UPI now handles half the world’s real-time digital payments.

James Whiteson

Sep 11, 202671 views
Nigerian Udu Technologies partners Baro AI to boost Africa's AI compute with GPUs

Nigerian Udu Technologies partners Baro AI to boost Africa's AI compute with GPUs

Nigerian Udu Technologies has teamed up with South Korean Baro AI to deliver high-performance GPUs across Africa, aiming to resolve the continent's AI computing shortage. The Seoul-signed deal targets long hardware delays.

Shagun Pandey

Sep 11, 202663 views