mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Quirso reports attackers exploit critical VMware vCenter flaw in 47 countries

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Quirso reports attackers exploit critical VMware vCenter flaw in 47 countries

German cybersecurity firm Quirso reported on Aug. 10 that a threat actor is actively exploiting a critical 9.8 directory traversal vulnerability in VMware vCenter (CVE-2026-59310) across 361 unique victim IP addresses in 47 countries, with Germany, the United States, Turkey, Iran and France the most affected. The attacker is using reverse SSH to maintain access to compromised systems, based on evidence from a recent incident response case. Broadcom has released a patch, even as security researchers warn that patching alone may not remove persistence already present.

CVE-2026-59310

CVE-2026-59310 is a directory traversal flaw rated 9.8 critical in VMware vCenter. It allows an attacker to manipulate file paths to access restricted directories and execute code across an enterprise virtual environment. VMware vCenter is the management control plane for ESXi hosts, virtual machines, storage and permissions. Broadcom, which owns VMware, has shipped a fix.

Exploitation Campaign

German cybersecurity firm Quirso said on Aug. 10 that a threat actor has been exploiting CVE-2026-59310 and using the reverse_ssh tool to maintain access, based on evidence from an incident response case. The campaign spans 361 unique victim IP addresses across 47 countries, with Germany, the United States, Turkey, Iran and France among the most affected. Quirso reported the attack chain uses a cron job and reverse_ssh to create an outbound connection to attacker infrastructure. Justin Beals, founder and CEO of Strike Graph, noted that 361 compromised systems across 47 countries appeared just five days after disclosure.

Persistence Risk

Denis Calderone, CTO of Suzu Labs, said a compromised vCenter gives an attacker control over every virtual machine, host and snapshot in the environment. Jason Soroko, senior fellow at Sectigo, said security teams should treat this as both a patching event and an incident-response event. Soroko warned that controls designed to block inbound SSH may not stop a compromised vCenter appliance from calling out via reverse_ssh, and that patching closes the entry point but does not remove persistence that may already exist. Beals said teams need to confirm remediation, watch for persistence mechanisms and treat vCenter with the same scrutiny as a domain controller. He added that attackers already have a five-day head start and most organizations have not caught up.

What's Next

Security researchers expect exploitation activity to keep growing before it slows, as attackers already have a five-day head start. It remains unclear how many organizations have patched CVE-2026-59310 or whether the reverse_ssh persistence mechanism has been fully evicted from compromised environments.

1 source

Quirso reports attackers exploit critical VMware vCenter flaw in 47 countries