Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Google Targets 2027 for First Major Post-Quantum Security Milestone

August 13, 2026

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

August 13, 2026

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charit

August 13, 2026
Facebook X (Twitter) Instagram
Friday, August 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»vCenter Flaw Exploited Just Five Days After Disclosure
News

vCenter Flaw Exploited Just Five Days After Disclosure

Team-CWDBy Team-CWDAugust 13, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems.

The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.

The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries while cautioning that an IP address does not necessarily correspond to a single organization.

The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code, turning a service built to collect logs into a route into the operating system.

Read more on VMware attacks: Play Ransomware Expands to Target VMware ESXi Environments

Five Days From Advisory to Compromise

Broadcom published advisory relating to the flaw on July 29, stating in an accompanying FAQ that it had not observed exploitation. It revised the advisory on August 3 to add 8.0 U2f express patches.

Quirso’s team said they first observed compromised systems contacting attacker infrastructure on August 3. The following day brought 151 further victim IPs, and by August 5 roughly 95% of the 361 total had appeared. Germany, the United States, Turkey, Iran and France accounted for 185 of them.

While the attacker may have had prior knowledge of the flaw, Quirso said the strong correlation between disclosure and exploitation points to the advisory as the campaign’s starting point.

Two Clocks to Manage

For persistence the actor deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing.

Because it dials outward rather than accepting inbound connections, it can bypass controls designed to block unsolicited inbound access. QUIRSO stressed that its presence alone is not proof of compromise.

Jason Soroko, senior fellow at certificate lifecycle management (CLM) provider Sectigo, said patching would not resolve the incident by itself. “There are therefore two clocks to manage,” he said, one for closing the vulnerability and one for evicting anyone who entered before the patch.

Broadcom has not published a workaround. Fixed vCenter releases are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the deployed branch, and address both critical vCenter flaws in the advisory, the exploited directory traversal and an authentication bypass in VMware Directory Service.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Next Article ICO Reprimands Criminal Records Office After 2023 Breach
Team-CWD
  • Website

Related Posts

News

Google Targets 2027 for First Major Post-Quantum Security Milestone

August 13, 2026
News

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

August 13, 2026
News

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charit

August 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A quick guide to recovering a hacked account

March 21, 2026

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Why children’s data is a long-term identity risk

June 3, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.