INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

VMware vCenter Vulnerability Exploit Attack

| 2026-08-12 09:01 CRITICAL MEDIUM
Executive Summary AI-generated
The threat landscape is increasingly shifting as Chinese threat actors continue to exploit vulnerabilities in widely used software, such as VMware vCenter. A recent patch for CVE-2026-59310 has been released by Broadcom but the vulnerability remains unpatched due to a spike in scanning efforts targeting vulnerable systems. This suggests that attackers are actively seeking out and exploiting these weaknesses. The threat actors behind this activity have demonstrated path traversal capabilities, using reverse_ssh tools to establish persistence on compromised hosts. Compromised systems were first identified five days after Broadcom publicly disclosed the flaw, indicating an accelerated exploitation effort. As a result, cybersecurity companies like QUIRSO GmbH are sounding the alarm about the potential for widespread attacks in the coming weeks and months.
Technical Mitigations AI-generated
* Implement a secure patching strategy for VMware vCenter and other affected products, including: + Regularly updating operating systems and applications to ensure they have the latest security patches. + Using vulnerability scanning tools to identify potential vulnerabilities before they can be exploited. + Ensuring that all users with access to these systems are properly authenticated and authorized. * Implement network segmentation and isolation techniques to limit the spread of malware and unauthorized access: + Use firewalls, intrusion detection/prevention systems (IDPS), and virtual private networks (VPNs) to block suspicious traffic. + Limit network access to critical services and applications using role-based access control (RBAC). + Implement a content delivery network (CDN) or load balancing system to distribute sensitive data across multiple locations. * Monitor for signs of exploitation and respond quickly in case of an incident: + Continuously monitor logs, systems, and networks for suspicious activity. + Establish incident response plans that include procedures for responding to CVE-2026-59310 attacks. + Engage with external experts and threat intelligence feeds to stay informed about potential threats. Note: These mitigations are not a substitute for proper security controls or incident response planning. They should be implemented in conjunction with these efforts to ensure comprehensive cybersecurity protection.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
DenisDenis CVE-2026-59310CVE-2026-59310 CVE-2026-41703CVE-2026-41703 CVE-2026-47876CVE-2026-47876 CVE-2026-41709CVE-2026-41709 CVE-2026-59309CVE-2026-59309
Target & Sectors
DACH DACH governmentgovernment technologytechnology
Incident Timeline
‎April 2025
Threat actors exploited CVE-2026-59309 in VMware vCenter to gain persistent remote access.
source_region China
industry Government
infrastructure Windows
attribution SentinelOne
attribution GoReShell
organisation COO
organisation QUIRSO GmbH
organisation The Hacker News
organisation POST /sdk/
‎December 2025
Threat actors exploited a VMware vCenter vulnerability to compromise affected systems and deploy BrickStorm malware.
source_region China
attribution CISA
attribution BrickStorm
‎2026/07/13
Threat actors exploited a recently disclosed vulnerability in VMware vCenter to gain persistent remote access.
‎Jul 29, 2026
Threat actors exploited a previously unknown vulnerability in VMware vCenter to gain persistent remote access.
‎August 3, five days
Broadcom publicly disclosed the vulnerability on August 3, five days after it was identified by QUIRSO.
organisation Broadcom
‎Aug 12, 2026
Threat actors exploited CVE-2026-59310, a directory-traversal vulnerability in VMware vCenter server.
organisation VMware
organisation SSH
organisation IP
infrastructure 361 unique IP addresses
organisation APT
‎VMSA-2026-0006
Threat actors exploited the unauth auth-bypass vulnerability in VMware vCenter, coinciding with a SAML SSO flow.
vulnerability CVE-2026-59309
vulnerability CVSS 9.8
organisation unauth auth-
‎2026/08/12
Broadcom has released security updates to address multiple critical vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion.
organisation CVE-2026
organisation CVSS
organisation VMware
organisation vCenter
organisation Vulnerability / Enterprise Security
organisation Fusion
organisation the VMware Directory Service
organisation Broadcom
infrastructure 8.0
infrastructure 9.3
organisation VMXNET3
organisation Important
organisation VMware Workstation and Fusion
organisation CVE-2026-41703
infrastructure 9.1.0
infrastructure 9.0.2
infrastructure 7.6
financial 25595025 ESXi-9.0.2.0100
organisation CVE-2026-41709
infrastructure 5.2.3
infrastructure 2.7
organisation VMware Workstation 26H1
organisation VMware Fusion 26H1
organisation VMware Cloud Foundation
organisation VMware vSphere Foundation
infrastructure 9.1
infrastructure 9.0
organisation ESX
organisation Workstation and Fusion
organisation the vSphere Client
organisation FAQ
organisation CrowdStrike
organisation EDR
organisation DoS
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
361
Unique Ip Addresses
Metrics
infrastructure
‎9.1.0
Software Version
Metrics
infrastructure
‎9.0.2
Software Version
Metrics
infrastructure
‎8.0
Software Version
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
‎9.1
Software Version
Metrics
infrastructure
‎9.3
Software Version
Metrics
infrastructure
‎7.6
Software Version
Metrics
financial
25,595,025
Esxi-9.0.2.0100
Metrics
infrastructure
‎5.2.3
Software Version
Metrics
infrastructure
‎2.7
Software Version