www.securityweek.com 13 Aug 2026, 09:06 UTC

VMware vCenter CVE-2026-59310 flaw lets APT groups run code

VMware vCenter CVE-2026-59310 flaw lets APT groups run code
CyberSIXT Evidence Panel
Primary Source support.broadcom.com
CISA KEV Listed in KEV
Patch Patch Available

THREAT actors are exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, disclosed on July 29 and patched by Broadcom. The flaw, rated 9.8 on the CVSS scale, is associated with directory traversal in the Syslog server allowing remote code execution. Advanced persistent threat (APT) groups have targeted vulnerable servers, with Quirso identifying over 360 compromised IP addresses across 47 countries, predominantly in Germany, the US, Turkey, Iran, and France.

Exploitation began shortly after the bug's disclosure, with attackers utilizing a reverse SSH shell for persistent access. Organizations are advised to validate detections to mitigate risks.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline