Global Threat Campaign Hits Critical VMware vCenter Flaw
Dark ReadingArchived Aug 14, 2026✓ Full text saved
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Full text archived locally
✦ AI Summary· Claude Sonnet
VULNERABILITIES & THREATS
APPLICATION SECURITY
CYBER RISK
CYBERSECURITY OPERATIONS
NEWS
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Rob Wright,Senior News Director,Dark Reading
August 13, 2026
4 Min Read
SOURCE: MABOHH VIA GETTY IMAGES
A critical vulnerability in VMware vCenter came under heavy exploitation via a single threat actor just days after public disclosure.
CVE-2026–59310 is a critical directory traversal flaw with a 9.8 CVSS score that VMware disclosed on July 29. According to VMware owner Broadcom, an attacker with network access to a vCenter instance can remotely exploit the vulnerability to execute arbitrary code in the target's virtual environment.
In a blog post this week, German incident-response (IR) firm QUIRSO said it observed exploitation activity on a global scale that stemmed from a single threat actor. During a recent IR engagement, QUIRSO's Threat Research team uncovered evidence that a suspected advanced persistent threat actor began exploiting the flaw on Aug. 3, less than a week after public disclosure.
CVE-2026–59310 is the latest VMware vulnerability to come under exploitation, though so far attacks appear to be limited to just the one suspected APT actor. But, the attacks once again demonstrate the short window between public disclosure and active exploitation for heavily targeted vendors like VMware.
Related:Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
A Global Threat Campaign Targeting VMware vCenter Users
The QUIRSO research team traced activity to 47 different countries, with the US, France, Iran, and Turkey as the most heavily targeted nations. In total, QUIRSO identified 361 unique IP addresses impacted by the threat campaign, though the company cautioned that the figure doesn't represent the number of total victims of the campaign, as some addresses belong to cloud or hosting providers and share infrastructure.
Unfortunately, patching the flaw may not be enough to fully mitigate the threat. The threat actor is establishing post-exploitation persistence through reverse_ssh, an open source tool for penetration testing that can be used to create outbound control channels from compromised systems.
Denis Szadkowski, chief operations officer (COO) and co-founder of QUIRSO, tells Dark Reading that if the threat actor exploited the flaw in a vulnerable vCenter instance and used reverse_ssh, the attacker's access will persist even after the software is updated to a fixed version.
"It is essentially a race between exploitation and patching," Szadkowski says. "We therefore recommend a forensic investigation of potentially affected systems to rule out an existing compromise."
QUIRSO published a YARA rule for identifying reverse_ssh builds, and urged organizations to review their vCenter instances for signs of compromise. While the campaign's activity peaked on Aug. 4, Szadkowski says attacks are ongoing.
Related:Coruna, DarkSword iOS Exploits Proliferate Globally
"We are still seeing new victims connecting to the attacker-controlled reverse_ssh infrastructure, and the attackers appear to be unaware that we are monitoring it," he says. "The number of new victims continues to increase, although more slowly than during the first days, as the number of unpatched, exploitable systems decreases over time."
Small Patching Windows for VMware Customers
In its blog post, QUIRSO noted that it's possible the threat actor had prior knowledge of vulnerability, but the time frame of attacks suggests the public disclosure of CVE-2026–59310 was the initial starting point of the campaign. Additionally, Szadkowski says five-day turnaround from disclosure to exploitation doesn't necessarily indicate the attacker has VMware expertise or experience with similar attacks.
"Skilled vulnerability researchers and advanced actors commonly perform patch diffing after disclosure," Szadkowski says. "We believe it is reasonable that a sufficiently skilled researcher could analyze the patch and develop an exploit within the five days between the advisory and the intrusion we investigated."
Nevertheless, the small window for which to patch vCenter presents significant challenges to organizations, according to Matt Snyder, principal engineer and detection and response lead at Aviatrix. A wide variety of threat actors, from cybercriminals gangs to nation-state groups, have focused on VMware products because the software is ubiquitous among enterprises, and acts as a key that can open every door in the building, he says.
Related:Flaws in Google APK for Python Unlock Agent-to-Agent Attack
"If a bad actor targets vCenter, the blast radius of a single unauthenticated RCE isn't one application; it's the whole estate," Snyder says.
Additionally, the complexity of virtual environments and hypervisors makes patching VMware products a more daunting task than your average application, and organizations are slow to patch "because the maintenance window is a conversation nobody wants to have," Snyder says.
"This operational lag is why defense strategies must center on network containment as the primary line of defense," he adds. "Organizations have to treat control planes like vCenter as untrusted zones, isolating management interfaces, enforcing strict network micro-segmentation, and restricting outbound connectivity to prevent reverse shells from establishing persistent command-and-control (C2) channels."
About the Author
Rob Wright
Senior News Director, Dark Reading
Rob Wright is a longtime reporter with more than 25 years of experience as a technology journalist. Prior to joining Dark Reading as senior news director, he spent more than a decade at TechTarget's SearchSecurity in various roles, including senior news director, executive editor and editorial director. Before that, he worked for several years at CRN, Tom's Hardware Guide, and VARBusiness Magazine covering a variety of technology beats and trends.
Prior to becoming a technology journalist in 2000, he worked as a weekly and daily newspaper reporter in Virginia, where he won three Virginia Press Association awards in 1998 and 1999. At TechTarget and Dark Reading, he has won several Azbee awards, including the 2026 National Silver Award for a series on vibe coding.
At Dark Reading, Rob currently covers security operations, cloud security, and Internet infrastructure. He has a keen interest in malvertising activity and the certificate authority industry, and has written extensively on both topics. He graduated from the University of Richmond in 1997 with a degree in journalism and English. A native of Massachusetts, he lives in the Boston area.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI
The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
More Webinars
Editor's Choice
CYBERSECURITY OPERATIONS
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
byArielle Waldman
AUG 6, 2026
4 MIN READ
APPLICATION SECURITY
Microsoft's Patch Tuesday Deluge Continues With August Updates
byJai Vijayan
AUG 11, 2026
4 MIN READ
CYBERATTACKS & DATA BREACHES
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
byRobert Lemos
AUG 12, 2026
4 MIN READ
Want more Dark Reading stories in your Google search results?
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE