INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
VMware vCenter Vulnerability Exploit Attack
| 2026-08-12 09:01 CRITICAL MEDIUMExecutive Summary AI-generated
The threat landscape is increasingly shifting as Chinese threat actors continue to exploit vulnerabilities in widely used software, such as VMware vCenter. A recent patch for CVE-2026-59310 has been released by Broadcom but the vulnerability remains unpatched due to a spike in scanning efforts targeting vulnerable systems. This suggests that attackers are actively seeking out and exploiting these weaknesses. The threat actors behind this activity have demonstrated path traversal capabilities, using reverse_ssh tools to establish persistence on compromised hosts. Compromised systems were first identified five days after Broadcom publicly disclosed the flaw, indicating an accelerated exploitation effort. As a result, cybersecurity companies like QUIRSO GmbH are sounding the alarm about the potential for widespread attacks in the coming weeks and months.
Technical Mitigations AI-generated
* Implement a secure patching strategy for VMware vCenter and other affected products, including:
+ Regularly updating operating systems and applications to ensure they have the latest security patches.
+ Using vulnerability scanning tools to identify potential vulnerabilities before they can be exploited.
+ Ensuring that all users with access to these systems are properly authenticated and authorized.
* Implement network segmentation and isolation techniques to limit the spread of malware and unauthorized access:
+ Use firewalls, intrusion detection/prevention systems (IDPS), and virtual private networks (VPNs) to block suspicious traffic.
+ Limit network access to critical services and applications using role-based access control (RBAC).
+ Implement a content delivery network (CDN) or load balancing system to distribute sensitive data across multiple locations.
* Monitor for signs of exploitation and respond quickly in case of an incident:
+ Continuously monitor logs, systems, and networks for suspicious activity.
+ Establish incident response plans that include procedures for responding to CVE-2026-59310 attacks.
+ Engage with external experts and threat intelligence feeds to stay informed about potential threats.
Note: These mitigations are not a substitute for proper security controls or incident response planning. They should be implemented in conjunction with these efforts to ensure comprehensive cybersecurity protection.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
DenisDenis
CVE-2026-59310CVE-2026-59310
CVE-2026-41703CVE-2026-41703
CVE-2026-47876CVE-2026-47876
CVE-2026-41709CVE-2026-41709
CVE-2026-59309CVE-2026-59309
Target & Sectors
DACH
DACH
governmentgovernment
technologytechnology
Incident Timeline
April 2025
Threat actors exploited CVE-2026-59309 in VMware vCenter to gain persistent remote access.
Click on any entity below to view its context and source!
source_region
China
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
industry
Government
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
infrastructure
Windows
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
attribution
SentinelOne
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
attribution
GoReShell
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
organisation
COO
Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.
organisation
QUIRSO GmbH
Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.
organisation
The Hacker News
Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.
organisation
POST /sdk/
"Our honeypots are logging increased fingerprinting – such as version probes via POST /sdk/
December 2025
Threat actors exploited a VMware vCenter vulnerability to compromise affected systems and deploy BrickStorm malware.
Click on any entity below to view its context and source!
source_region
China
In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to
deploy BrickStorm malware
, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft.
attribution
CISA
In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to
deploy BrickStorm malware
, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft.
attribution
BrickStorm
In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to
deploy BrickStorm malware
, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft.
2026/07/13
Threat actors exploited a recently disclosed vulnerability in VMware vCenter to gain persistent remote access.
Jul 29, 2026
Threat actors exploited a previously unknown vulnerability in VMware vCenter to gain persistent remote access.
August 3, five days
Broadcom publicly disclosed the vulnerability on August 3, five days after it was identified by QUIRSO.
Click on any entity below to view its context and source!
organisation
Broadcom
Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaw.
Aug 12, 2026
Threat actors exploited CVE-2026-59310, a directory-traversal vulnerability in VMware vCenter server.
Click on any entity below to view its context and source!
organisation
VMware
The vulnerability in question is
CVE-2026-59310
(CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code.
organisation
SSH
The attack chain is said to have exhibited path traversal activity consistent with the flaw, followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh, an open-source tool used for setting up SSH connections to threat actor-controlled infrastructure.
organisation
IP
In all, there are as many as 361 unique victim IP addresses located across 47 countries.
infrastructure
361 unique IP addresses
In all, there are as many as 361 unique victim IP addresses located across 47 countries.
organisation
APT
It's not clear who is behind the exploitation campaign, but it's believed to be the work of a suspected advanced persistent threat (APT) actor.
VMSA-2026-0006
Threat actors exploited the unauth auth-bypass vulnerability in VMware vCenter, coinciding with a SAML SSO flow.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-59309
SAML SSO flow – coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8)," the cybersecurity company said.
vulnerability
CVSS 9.8
SAML SSO flow – coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8)," the cybersecurity company said.
organisation
unauth auth-
SAML SSO flow – coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8)," the cybersecurity company said.
2026/08/12
Broadcom has released security updates to address multiple critical vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion.
Click on any entity below to view its context and source!
organisation
CVE-2026
CVE-2026-59310:
A critical directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker with network access to execute arbitrary code.
organisation
CVSS
The three critical vulnerabilities are the two vCenter flaws, CVE-2026-59309 and CVE-2026-59310, which have CVSS scores of 9.8, and the VMXNET3 escape flaw, CVE-2026-47876, which is rated 9.3.
The second critical flaw is a directory-traversal vulnerability in vCenter (
CVE-2026-59310
, CVSS score: 9.8) that a malicious actor with network access can exploit to execute arbitrary code.
organisation
VMware
VMware fixes three critical flaws allowing auth bypass, VM escapes.
VM Escape.
Ravie Lakshmanan
Jul 29, 2026
Vulnerability / Enterprise Security
Broadcom has
released
security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
organisation
vCenter
VM Escape.
Ravie Lakshmanan
Jul 29, 2026
Vulnerability / Enterprise Security
Broadcom has
released
security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system.
organisation
Vulnerability / Enterprise Security
VM Escape.
Ravie Lakshmanan
Jul 29, 2026
Vulnerability / Enterprise Security
Broadcom has
released
security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
organisation
Fusion
VM Escape.
Ravie Lakshmanan
Jul 29, 2026
Vulnerability / Enterprise Security
Broadcom has
released
security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
organisation
the VMware Directory Service
The five vulnerabilities are summarized below:
CVE-2026-59309:
A critical authentication bypass vulnerability in the VMware Directory Service.
organisation
Broadcom
Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.
VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)
Also patched by Broadcom are three other flaws -
CVE-2026-47876
(CVSS score: 9.3) -
infrastructure
8.0
VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)
Also patched by Broadcom are three other flaws -
CVE-2026-47876
(CVSS score: 9.3) -
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
"The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a "back in time" error.
infrastructure
9.3
VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)
Also patched by Broadcom are three other flaws -
CVE-2026-47876
(CVSS score: 9.3) -
organisation
VMXNET3
CVE-2026-47876:
A critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.
An out-of-bounds write vulnerability in the VMXNET3 virtual network adapter of VMware ESX that a malicious actor with local administrative privileges on a virtual machine can exploit to execute code on the host.
organisation
Important
The remaining issues are less severe, with CVE-2026-41703 rated as Important with a score of 7.6 on ESX.
organisation
VMware Workstation and Fusion
VMware Workstation and Fusion users running version 25H2 must upgrade to 26H1 to address CVE-2026-41703.
On VMware Workstation and Fusion, the impact is limited to information disclosure.
organisation
CVE-2026-41703
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
infrastructure
9.1.0
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389)
infrastructure
9.0.2
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389)
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
infrastructure
7.6
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
financial
25595025 ESXi-9.0.2.0100
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
organisation
CVE-2026-41709
CVE-2026-41709 is also rated Low at 2.7.
infrastructure
5.2.3
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
infrastructure
2.7
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
organisation
VMware Workstation 26H1
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
organisation
VMware Fusion 26H1
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
organisation
VMware Cloud Foundation
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
organisation
VMware vSphere Foundation
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
infrastructure
9.1
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
infrastructure
9.0
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
"The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a "back in time" error.
organisation
ESX
An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape.
"An attacker who already holds local administrative privileges inside a virtual machine that uses the VMXNET3 virtual network adapter may execute code on the ESX host," it
said
.
organisation
Workstation and Fusion
On Workstation and Fusion, the impact is limited to information disclosure.
organisation
the vSphere Client
Broadcom says patching vCenter temporarily interrupts access to the vSphere Client and other management interfaces, but running virtual machines and containers will continue operating.
organisation
FAQ
A "back in time" restriction occurs when a patch updates a product branch that carries a newer build number than the target of a planned upgrade," explains the FAQ.
organisation
CrowdStrike
CrowdStrike has also observed attackers using the ESXi shell to create unregistered "ghost" virtual machines that do not appear in the ESXi or vCenter web consoles, a persistence technique the company tracks as
VirtualGHOST
.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
DoS
An out-of-bounds read vulnerability in VMware ESX that a malicious actor with VM deployment privileges could trigger, potentially leading to information disclosure or a denial-of-service (DoS) condition.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
In April 2025, SentinelOne
disclosed
details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
Metrics
infrastructure
361
Unique Ip Addresses
In all, there are as many as 361 unique victim IP addresses located across 47 countries.
Metrics
infrastructure
9.1.0
Software Version
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389)
Metrics
infrastructure
9.0.2
Software Version
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3j-25429389)
Metrics
infrastructure
8.0
Software Version
The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k.
"The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a "back in time" error.
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)
Also patched by Broadcom are three other flaws -
CVE-2026-47876
(CVSS score: 9.3) -
Metrics
infrastructure
9.0
Software Version
"The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a "back in time" error.
VMware Cloud Foundation, VMware vSphere Foundation versions 9.0.x.x (Fixed in 9.0.2.0100)
VMware vCenter version 8.0 (Fixed in 8.0 U3k)
Metrics
infrastructure
9.1
Software Version
Both vulnerabilities have been addressed in the versions below -
VMware Cloud Foundation, VMware vSphere Foundation versions 9.1.x.x (Fixed in 9.1.0.0300)
Metrics
infrastructure
9.3
Software Version
VMware Cloud Foundation versions 5.x (Async patch to 8.0 U3k)
Also patched by Broadcom are three other flaws -
CVE-2026-47876
(CVSS score: 9.3) -
Metrics
infrastructure
7.6
Software Version
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
Metrics
financial
25,595,025
Esxi-9.0.2.0100
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0200-25557999 and ESXi-9.0.2.0100-25595025, and VMware ESX ESXi80U3k-25595708)
CVE-2026-41703
(CVSS score: 7.6) -
Metrics
infrastructure
5.2.3
Software Version
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
Metrics
infrastructure
2.7
Software Version
(Fixed in VMware Cloud Foundation and VMware vSphere Foundation versions ESXi-9.1.0.0-25370933 and ESXi-9.0.2.0100-25595025, VMware ESX ESXi80U3i-25205845, VMware Workstation 26H1, VMware Fusion 26H1, and VMware Cloud Foundation 5.2.3)
CVE-2026-41709
(CVSS score: 2.7) -
Intelligence Sources
The Hacker News
2026-07-29
BleepingComputer
2026-07-30
VMware fixes three critical flaws allowing auth bypass, VM escapes
BleepingComputer
The Hacker News
2026-08-12
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-13T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
VMware
entity
9x
timeline
Temporal Reference
April 2025
date
9x
infrastructure
Software Version
9.1.0
version
6x
attribution
Attributing Entity
SentinelOne
authority
5x
vulnerability
Exploited CVE
CVE-2026-59310
cve
3x
target region
Target Country
Germany
country
3x
general metric
Score
10
score
2x
source region
Origin Country
China
country
2x
industry
Targeted Sector
Government
sector
2x
tactic
Cyber Operation Type
Espionage
tactic
2x
general metric
%
54
%
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Windows
software
vulnerability
CVSS Score
10
score
malware
Malware Payload
Denis
tool
general metric
Aug
12
aug
infrastructure
Unique Ip Addresses
361
unique ip addresses
general metric
Countries
47
countries
general metric
Cve-2026
9
cve-2026
general metric
Update 3K
8
update 3k
financial
Esxi-9.0.2.0100
25,595,025
esxi-9.0.2.0100
general metric
Jul
29
jul
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.