CVE Tools
Back to feed
Exploited in the wild VMware vCenter cloud Broadcom rce

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom’s VMware vCenter, to gain remote code execution capabilities. German security firm QUIRSO confirmed active attacks affecting at least 361 victim IPs across 47 countries, beginning five days after the official disclosure. Attackers established persistence by deploying malicious cron jobs using reverse_ssh to connect back to their infrastructure, likely driven by an advanced persistent threat group.