VMware vCenter Vulnerability Exploited for Persistent Remote Access by Threat Actors
Threat actors are exploiting a critical VMware vCenter vulnerability (CVE-2026-59310) to achieve persistent remote access through directory-traversal and reverse_ssh techniques, with evidence linking the attacks to an advanced persistent threat (APT) group. The breach affects 361 unique IP addresses across 47 countries, highlighting urgent patch management needs for enterprise systems.
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were
*** END OF TRANSMISSION ***