Attackers Actively Exploiting Critical VMware vCenter Vulnerability (CVE-2026-59310)

Threat actors have begun actively exploiting a recently patched critical security flaw (CVE-2026-59310) in Broadcom VMware vCenter. This directory-traversal vulnerability allows a malicious actor with network access to execute arbitrary code, with patches released late last month. Cybersecurity firm QUIRSO discovered the activity, noting attack chains consistent with the flaw and the deployment of malicious cron jobs for persistence. Compromised systems were found to contact attacker domains five days after public disclosure, affecting 361 unique IP addresses across 47 countries.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai