Exploited in the wild VMware vCenter cloud Broadcom rce
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
CVE Tools coverage
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, to gain remote code execution capabilities. German security firm QUIRSO confirmed active attacks affecting at least 361 victim IPs across 47 countries, beginning five days after the official disclosure. Attackers established persistence by deploying malicious cron jobs using reverse_ssh to connect back to their infrastructure, likely driven by an advanced persistent threat group.