High cybersecurity update: Global Threat Campaign Hits Critical VMware vCenter Flaw. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.

What Happened

Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat. Global Threat Campaign Hits Critical VMware vCenter Flaw Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat. Rob Wright , Senior News Director , Dark Reading A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure. CVE-2026–59310 is a critical directory traversal flaw with a 9.8 CVSS score that VMware disclosed on July 29. According to VMware owner Broadcom, an attacker with network access to a vCenter instance can remotely exploit the vulnerability to execute arbitrary code in the target's virtual environment. In a blog post this week, German incident-response (IR) firm QUIRSO said it observed exploitation activity on a global scale that stemmed from a single threat actor. During a recent IR engagement, QUIRSO's Threat Research team uncovered evidence that a suspected advanced persistent threat actor began exploiting the flaw on Aug. CVE-2026–59310 is the latest VMware vulnerability to come under exploitation , though so far attacks appear to be limited to just the one suspected APT actor.

Technical Details

But, the attacks once again demonstrate the short window between public disclosure and active exploitation for heavily targeted vendors like VMware . Related: Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A Global Threat Campaign Targeting VMware vCenter Users The QUIRSO research team traced activity to 47 different countries, with the US, France, Iran, and Turkey as the most heavily targeted nations. In total, QUIRSO identified 361 unique IP addresses impacted by the threat campaign, though the company cautioned that the figure doesn't represent the number of total victims of the campaign, as some addresses belong to cloud or hosting providers and share infrastructure. Unfortunately, patching the flaw may not be enough to fully mitigate the threat. The threat actor is establishing post-exploitation persistence through reverse_ssh, an open source tool for penetration testing that can be used to create outbound control channels from compromised systems. Denis Szadkowski, chief operations officer (COO) and co-founder of QUIRSO, tells Dark Reading that if the threat actor exploited the flaw in a vulnerable vCenter instance and used reverse_ssh, the attacker's access will persist even after the software is updated to a fixed version. "It is essentially a race between exploitation and patching," Szadkowski says. "We therefore recommend a forensic investigation of potentially affected systems to rule out an existing compromise." QUIRSO published a YARA rule for identifying reverse_ssh builds, and urged organizations to review their vCenter instances for signs of compromise. While the campaign's activity peaked on Aug.

Security Impact

Organizations using the affected technology should treat the report according to its high severity classification. 4, Szadkowski says attacks are ongoing. "We are still seeing new victims connecting to the attacker-controlled reverse_ssh infrastructure, and the attackers appear to be unaware that we are monitoring it," he says. "The number of new victims continues to increase, although more slowly than during the first days, as the number of unpatched, exploitable systems decreases over time." In its blog post, QUIRSO noted that it's possible the threat actor had prior knowledge of vulnerability, but the time frame of attacks suggests the public disclosure of CVE-2026–59310 was the initial starting point of the campaign. Additionally, Szadkowski says five-day turnaround from disclosure to exploitation doesn't necessarily indicate the attacker has VMware expertise or experience with similar attacks. "Skilled vulnerability researchers and advanced actors commonly perform patch diffing after disclosure," Szadkowski says. "We believe it is reasonable that a sufficiently skilled researcher could analyze the patch and develop an exploit within the five days between the advisory and the intrusion we investigated." Nevertheless, the small window for which to patch vCenter presents significant challenges to organizations, according to Matt Snyder, principal engineer and detection and response lead at Aviatrix. A wide variety of threat actors, from cybercriminals gangs to nation-state groups, have focused on VMware products because the software is ubiquitous among enterprises, and acts as a key that can open every door in the building, he says.

Recommended Actions

  • Identify whether the affected product, service or software is present in the environment.
  • Review the original vendor or research advisory and verify affected versions before making configuration changes.
  • Apply vendor-provided security updates or mitigations as soon as operationally practical.
  • Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
  • Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.

Security Details

  • Severity: High
  • Original source: Dark Reading

Why This Matters

Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.

Original Report

NetworkFix recommends reviewing the complete original report from Dark Reading for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.