www.securityweek.com 8/13/2026, 9:21:10 AM · external

VMware vCenter CVE-2026-59310 flaw lets APT groups run code

VMware vCenter CVE-2026-59310 flaw lets APT groups run code
Developing story vulnerability 4 articles tracked
Broadcom patches multiple critical VMware vCenter and ESXi vulnerabilities
CyberSIXT Evidence Panel
Primary Source support.broadcom.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THREAT actors are exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, disclosed on July 29 and patched by Broadcom. The flaw, rated 9.8 on the CVSS scale, is associated with directory traversal in the Syslog server allowing remote code execution. Advanced persistent threat (APT) groups have targeted vulnerable servers, with Quirso identifying over 360 compromised IP addresses across 47 countries, predominantly in Germany, the US, Turkey, Iran, and France.

Exploitation began shortly after the bug's disclosure, with attackers utilizing a reverse SSH shell for persistent access. Organizations are advised to validate detections to mitigate risks.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline