Articles

VMware vCenter CVE-2026-59310 Exploited in the Wild

A critical CVSS 9.8 directory-traversal flaw in VMware vCenter is under active attack across 47 countries. Affected versions, the exploit chain, and the fix.

Chisato Chisato · · 4 min read
A figure working at a keyboard in a dark room, representing an active exploitation campaign

A flaw at the heart of enterprise virtualization is now being exploited at scale. Security researchers say attackers are actively targeting CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, using it to plant persistent remote access on servers around the world. Broadcom, which owns VMware, rated the bug CVSS 9.8 and warned that an attacker with network access can exploit it to execute arbitrary code — and the window between disclosure and mass exploitation has been strikingly short.

vCenter is not an ordinary application. It is the central management plane for VMware virtualized environments, the console administrators use to control clusters of ESXi hosts and the virtual machines running on them. Compromising it can hand an attacker broad reach across an organization’s server estate, which is why a wormable-adjacent flaw in this product draws immediate attention.

The vulnerability

CVE-2026-59310 is a directory-traversal (path-traversal) flaw in vCenter’s Syslog server component. Broadcom disclosed and patched it on July 29, 2026, bundling the fix alongside four other security defects across multiple VMware products. Directory-traversal bugs let an attacker escape an intended file path and reach locations they should not — and in this case the flaw can be chained to arbitrary code execution on the underlying host, which is what elevates it from serious to critical.

The CVSS 9.8 score reflects the combination that makes these bugs dangerous: network-accessible, low-complexity, and no authentication required in the exploited path. Against a management server that typically sits deep inside a trusted network segment, that profile is close to worst case.

From patch to attack in under a week

The timeline is the alarming part. Broadcom shipped the fix on July 29. By August 3 — less than a week later — threat researchers observed a coordinated campaign already exploiting unpatched systems. That five-day gap is a textbook illustration of how quickly disclosure now converts into exploitation, and how little runway defenders get once a patch reveals the vulnerable code path to attackers.

Researchers attributed the activity to a suspected advanced persistent threat (APT) actor and tracked its spread across the internet. As of the latest reporting, the campaign had touched 361 distinct victim IP addresses across 47 countries — a global footprint consistent with mass scanning followed by targeted follow-on activity, rather than a single opportunistic intrusion.

The exploit chain

The observed attacks followed a consistent pattern. First came path-traversal activity matching the CVE-2026-59310 signature — the initial exploitation of the Syslog component. Attackers then established persistence by deploying a malicious cron job on the compromised host, ensuring their access survived reboots and routine maintenance.

The persistence tooling of choice was reverse_ssh, an open-source utility that sets up SSH connections back to attacker-controlled infrastructure. Because the victim initiates the outbound connection, reverse-SSH tunnels are effective at slipping past firewalls that block inbound traffic — the machine “phones home,” and the attacker rides that channel back in. It is a lightweight, hard-to-spot way to maintain long-term control of a management server.

That combination — traversal to code execution, a cron job for persistence, reverse SSH for command and control — describes a threat actor interested in durable access, not a smash-and-grab. On a platform that controls entire virtualized fleets, durable access is exactly the foothold from which lateral movement and data theft begin.

Who is exposed and what to do

Any organization running an unpatched vCenter Server with the affected Syslog component reachable on the network is at risk. Because vCenter underpins so much enterprise infrastructure, exposure is widespread across sectors. The remediation guidance is direct:

  • Apply Broadcom’s July 29 patch immediately if you have not already. Given confirmed in-the-wild exploitation, this is an emergency-change candidate rather than a next-maintenance-window item.
  • Restrict network access to vCenter management interfaces, ensuring they are not exposed to untrusted networks or the public internet.
  • Hunt for compromise. Look for unexpected cron jobs, unfamiliar outbound SSH connections, and reverse_ssh artifacts on vCenter hosts — patching a machine that is already backdoored does not evict the intruder.

The active-exploitation status means the usual patch-when-convenient calculus does not apply. This is a live campaign against a high-value target.

What it means

CVE-2026-59310 is another entry in a growing pattern of critical flaws in enterprise infrastructure being weaponized within days of disclosure. It sits alongside the maximum-severity Metabase zero-day and the actively exploited N-able N-central flaw as evidence that management and infrastructure software — the systems that control everything else — has become the attacker’s preferred entry point.

Why management planes are the target. Compromise a laptop and you own a laptop; compromise vCenter and you can influence every virtual machine it manages. Attackers have learned that the highest return comes from the software that sits above the workloads, which is why platforms like vCenter, identity providers, and remote-management tools keep drawing coordinated campaigns. The broader wave of infrastructure zero-days this year reflects the same logic.

The patch-gap problem. Five days from patch to mass exploitation leaves almost no margin. Publishing a fix now effectively hands attackers a map of the vulnerable code, and automated tooling turns that map into working exploits fast. For defenders, the practical takeaway is uncomfortable but clear: the response window for critical infrastructure CVEs is measured in days, not weeks, and patch cadence for internet- or network-adjacent management systems has to reflect that.

What to watch. First, whether exploitation broadens beyond the initial APT to commodity ransomware crews, which typically follow high-value flaws once proof-of-concept tooling circulates. Second, whether the 361 observed victims mark the leading edge of a larger campaign as scanning continues. And third — the enduring lesson from the year’s patch-cycle disclosures — how many organizations still have vCenter exposed weeks after the fix shipped. In infrastructure security, the vulnerability is only half the story; the patch gap is the other half, and it is the half attackers are counting on.

Chisato Chisato · · 6 min read

Chrome Zero-Day CVE-2026-85046: V8 Flaw Exploited

Google patched CVE-2026-85046, an actively exploited V8 type-confusion zero-day in Chrome and the sixth of 2026. Affected versions, the risk, and how to patch.

#Security #Zero-Day #Chrome
Chisato Chisato · · 5 min read

PaperCut NG/MF Zero-Day: Patch All Versions Now

PaperCut is patching two zero-days in NG and MF — a pre-auth RCE and an access-control flaw — exploited in the wild. All versions affected. Apply Release 2.

#Security #Cybersecurity #Zero-Day
Chisato Chisato · · 7 min read

Lazarus Windows Zero-Day: Operation Dream Job Returns

North Korea's Lazarus group exploited a Windows AFD.sys zero-day (CVE-2026-68820) for five weeks to breach defense firms and deploy the FudModule rootkit.

#Security #Zero-Day #Cybersecurity