Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, tracked as CVE-2026-59310 (CVSS 9.8), to gain persistent remote access to affected systems. The flaw, which allows remote code execution, was patched by Broadcom in late July 2026. According to German cybersecurity firm QUIRSO, the exploitation was discovered during an incident response engagement and involves path traversal followed by the deployment of a malicious cron job that establishes persistence using the open-source tool reverse_ssh.
QUIRSO identified 361 unique victim IP addresses across 47 countries, with the highest concentrations in Germany, the U.S., Turkey, Iran, and France. The first contact with attacker-controlled domains occurred on August 3, 2026, just five days after Broadcom’s public disclosure, suggesting a strong correlation between disclosure and exploitation. While the identity of the attackers remains unknown, the activity is suspected to be the work of an advanced persistent threat (APT) actor.
VMware vCenter has historically been a prime target for Chinese threat actors such as UNC5174, who have exploited similar flaws in espionage campaigns. In April 2025, SentinelOne disclosed a related threat cluster called PurpleHaze that used a Windows backdoor named GoReShell, which leverages reverse_ssh functionality. The use of reverse_ssh is notable because it enables outbound connections to attacker-controlled endpoints, bypassing inbound security controls.
QUIRSO cautions that the presence of reverse_ssh alone is not proof of malicious activity, but when combined with unauthorized installation, unexpected outbound connections, or execution on a vulnerable vCenter appliance, it becomes a high-priority indicator requiring investigation.
Separately, Defused Cyber reported a spike in scanning activity targeting VMware vCenter, potentially exploiting another critical flaw, CVE-2026-59309 (CVSS 9.8), an unauthenticated authentication bypass in vmdir. However, QUIRSO’s COO Denis Szadkowski stated there is insufficient evidence to link the CVE-2026-59309 scanning with the intrusion set behind CVE-2026-59310. Organizations using VMware vCenter are urged to apply the latest patches immediately and monitor for indicators of compromise.
CVEs: CVE-2026-59310, CVE-2026-59309
Attack groups: UNC5174, PurpleHaze
Malware: GoReShell, reverse_ssh
Companies: Broadcom, QUIRSO, Defused Cyber, SentinelOne
Products: VMware vCenter
Original source: thehackernews.com