Hackers exploit critical VMware vCenter flaw for remote access

 

Hackers exploit critical VMware vCenter flaw for remote access

Threat actors are actively exploiting a critical security flaw in Broadcom’s VMware vCenter Server, according to new research from German cybersecurity company QUIRSO.

The vulnerability, tracked as CVE-2026-59310, allows attackers with network access to use directory traversal to execute arbitrary code on affected vCenter servers. Broadcom released patches for the flaw in late July.

Researchers discovered the attacks during an incident response investigation. The attackers used path traversal techniques before installing a malicious cron job to maintain access. The malware used reverse_ssh, an open-source tool that creates SSH connections to attacker-controlled systems.

QUIRSO identified up to 361 victim IP addresses across 47 countries. Most affected systems were in Germany, the United States, Turkey, Iran and France. The first known connections to attacker-controlled domains were observed on August 3, just five days after the vulnerability was publicly disclosed.

It’s not clear what threat actor is behind the campaign. VMware products have previously been targeted by Chinese-linked APT groups, including UNC5174, in espionage campaigns.

Organizations using VMware vCenter Server are recommended to apply security updates as soon as possible and check their systems for signs of unauthorized access.


Back to the list