CVE Tools

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker NewsBy The Hacker News

Reported exploitedVMware vCenter

Our summary

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, to gain remote code execution capabilities. German security firm QUIRSO confirmed active attacks affecting at least 361 victim IPs across 47 countries, beginning five days after the official disclosure. Attackers established persistence by deploying malicious cron jobs using reverse_ssh to connect back to their infrastructure, likely driven by an advanced persistent threat group.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store