UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

VMware vCenter Exploitation 2026: UK Patch Urgency

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

A suspected China-nexus threat actor is actively exploiting a critical directory-traversal flaw in Broadcom VMware vCenter Server, tracked as CVE-2026-59310, to gain arbitrary code execution on exposed management systems. For UK operators still running vCenter in production, this is no longer a theoretical risk — it is happening now, and the window to implement robust vulnerability management has already narrowed.

Victim IPs by Country (Top 5 Observed)
60 IPs45 IPs30 IPs15 IPs0 IPs55 IPsGermany41 IPsUS38 IPsTurkey26 IPsIran25 IPsFranceVictim IPs
View the data behind this chart
Victim IPs by Country (Top 5 Observed)
GermanyUSTurkeyIranFrance
Victim IPsIPs55IPs41IPs38IPs26IPs25

What's actually happening

Security researchers at QUIRSO, corroborated by Broadcom, The Hacker News and BleepingComputer, have identified an active exploitation campaign against Broadcom VMware vCenter Server. The vulnerability, CVE-2026-59310, is a directory-traversal flaw that allows an attacker to achieve arbitrary code execution on exposed vCenter instances.

Broadcom itself confirmed the risk directly, stating it had "information to suggest that exploitation of CVE-2026-59310 has occurred in the wild." That is about as unambiguous a signal as a vendor gives — this is not a low-probability advisory footnote, it is a confirmed, live attack path.

The vulnerability, in plain terms

CVE-2026-59310 carries a CVSS score of 9.8 — as close to maximum severity as the scale allows. Broadcom released a fix on 29 July 2026. That fix is now fully shipped; there is no ambiguity about patch availability, and any lingering description of the flaw as 'newly patched' understates the current reality: the patch has been out for weeks and is being actively bypassed on unpatched systems.

Adding to the pressure, one compromised vCenter Server Appliance was found targeted by both CVE-2026-59310 and a second flaw, CVE-2026-59309, an authentication-bypass vulnerability that is also seeing active scanning activity. Where both weaknesses exist on the same appliance, an attacker effectively has two independent routes into the management plane.

How fast attackers moved after disclosure

QUIRSO's telemetry shows compromised systems first contacted attacker-controlled infrastructure on 3 August 2026 — described as just five days after the flaw's public disclosure. That turnaround is the real lesson for UK buyers: patch cycles measured in weeks are no longer fast enough for internet-facing management infrastructure of this criticality.

Once inside, the actor has been observed deploying a backdoor alongside reverse_ssh binaries to establish persistence and maintain remote access, a detail independently confirmed by BleepingComputer's reporting on the same campaign. This isn't opportunistic defacement — it's infrastructure built for long-term footholds inside virtualisation environments.

Illustration: VMware vCenter Exploitation 2026: UK Patch Urgency

Scale: this is a global sweep, not a targeted hit

QUIRSO's data puts the observed footprint at 361 unique victim IP addresses spread across 47 countries. Germany leads with 55 affected addresses, followed by the United States (41), Turkey (38), Iran (26) and France (25). The UK is not called out separately in the disclosed figures, but a campaign spanning this many countries and this volume of victim infrastructure should be treated as a mass-exploitation event rather than a narrow, geographically confined incident.

That scale matters for prioritisation. Attackers running automated exploitation at this breadth are typically scanning broadly and compromising whatever exposed, unpatched vCenter instances they find — meaning exposure, not sector or size, is the deciding factor in whether an organisation gets hit.

Who's behind it — and why attribution is still soft

QUIRSO assessed with moderate confidence that the campaign is being run by a Chinese-speaking threat actor likely operating in the UTC+08:00 timezone. That is a meaningful signal, not a confirmed attribution to a named group — public reporting across QUIRSO, Broadcom, The Hacker News and BleepingComputer agrees on the technical facts (CVE-2026-59310, CVSS 9.8, active exploitation) but the precise intrusion set identity remains unresolved.

For defenders, the attribution nuance matters less than the behaviour: this actor profile is consistent with patterns seen in prior China-linked campaigns against VMware infrastructure, where virtualisation layers are targeted specifically because compromising the hypervisor management plane gives access to everything running on top of it.

What UK infrastructure teams should do this week

The immediate action is unambiguous: confirm the July patch for CVE-2026-59310 is applied across every vCenter Server Appliance in the estate, and check exposure to CVE-2026-59309 on the same systems given the observed dual-exploitation. If vCenter management interfaces are reachable from the internet or from broad internal segments without strict access controls, that exposure needs closing regardless of patch status.

Beyond patching, teams should hunt specifically for reverse_ssh artefacts and unexpected outbound connections from vCenter appliances, since that is the documented persistence mechanism in this campaign. Organisations without in-house threat-hunting capacity should look at managed detection & response to get eyes on this pattern quickly, and should develop a strong incident response plan specifically covering hypervisor-layer compromise scenarios, which behave very differently from endpoint incidents.

Longer term, this campaign is another data point for organisations weighing their platform roadmap. Repeated critical, actively-exploited vCenter vulnerabilities are a legitimate input into decisions to navigate VMware after Broadcom's acquisition, whether that means tightening operational discipline around the existing estate or reassessing the platform altogether via a look at the best VMware alternatives and a realistic calculation of migration costs. Either way, teams should keep a close eye on Broadcom's advisory cadence and stay informed on Broadcom VMware patches as this campaign continues to develop.

Share
Key takeaways
  • CVE-2026-59310 (CVSS 9.8) in Broadcom VMware vCenter Server is being actively exploited by a suspected China-nexus actor to gain arbitrary code execution.
  • Attackers began contacting compromised systems just five days after public disclosure, despite Broadcom's fix having shipped on 29 July 2026.
  • QUIRSO recorded 361 unique victim IPs across 47 countries, with Germany, the US, Turkey, Iran and France showing the heaviest concentrations.
  • Some compromised appliances were targeted via both CVE-2026-59310 and the related auth-bypass flaw CVE-2026-59309, so patch and access-control checks must cover both.
Frequently asked

FAQs — VMware vCenter Exploitation 2026

Is CVE-2026-59310 still exploitable if I've already patched?

No — Broadcom's fix, released on 29 July 2026, closes the flaw. The urgent risk applies to unpatched vCenter Server Appliances still exposed to exploitation, so confirming patch application across the entire estate is the priority action.

How do I know if my vCenter environment has already been compromised?

Look for reverse_ssh binaries, unexpected outbound connections and backdoor artefacts on vCenter appliances, as documented by BleepingComputer's independent reporting on this campaign. Organisations lacking this capability internally should consider managed detection & response support.

Is this the same actor behind other VMware campaigns?

QUIRSO assessed with only moderate confidence that a Chinese-speaking actor likely operating in UTC+08:00 is behind this campaign — it has not been definitively tied to a named group, and public reporting agrees on the technical facts but not a confirmed intrusion set identity.

Should this campaign change our VMware platform strategy?

It's a strong input, not a standalone reason. Combined with ongoing licensing changes, it's worth reviewing options to understand Broadcom's VMware pricing changes alongside your security posture when planning next steps.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111