VMware vCenter CVE-2026-59310 Under Active Exploitation with 361 Victims Across 47 Countries
Scope: VMware vCenter Server All Versions Prior to VMSA-2026-0006.1 Patched Releases
Severity: Red
QUIRSO confirmed today, August 12, 2026, that threat actors have been actively exploiting CVE-2026-59310 (CVSS 9.8), a directory traversal vulnerability in VMware vCenter, following an incident response engagement that revealed attacker activity beginning as early as August 3, just five days after Broadcom publicly disclosed the flaw. Post-exploitation activity included deployment of a malicious cron job establishing persistent reverse SSH connections to attacker-controlled infrastructure using reverse_ssh, an open-source tunneling tool previously linked to Chinese APT group PurpleHaze. QUIRSO identified 361 unique victim IP addresses across 47 countries, with the attacker infrastructure suggesting a suspected APT actor. Separately, Defused Cyber is observing a spike in fingerprinting activity against vCenter targeting the companion authentication bypass flaw CVE-2026-59309. Organizations that have not yet applied VMSA-2026-0006.1 patches must do so immediately, restrict vCenter to internal networks only, and check for unauthorized cron jobs and unexpected outbound SSH connections as indicators of prior compromise.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.