A suspected China-nexus threat actor is actively exploiting a critical directory-traversal flaw in Broadcom VMware vCenter Server, tracked as CVE-2026-59310, to gain arbitrary code execution on exposed management systems. For UK operators still running vCenter in production, this is no longer a theoretical risk — it is happening now, and the window to implement robust vulnerability management has already narrowed.
View the data behind this chart
| Germany | US | Turkey | Iran | France | |
|---|---|---|---|---|---|
| Victim IPs | IPs55 | IPs41 | IPs38 | IPs26 | IPs25 |
What's actually happening
Security researchers at QUIRSO, corroborated by Broadcom, The Hacker News and BleepingComputer, have identified an active exploitation campaign against Broadcom VMware vCenter Server. The vulnerability, CVE-2026-59310, is a directory-traversal flaw that allows an attacker to achieve arbitrary code execution on exposed vCenter instances.
Broadcom itself confirmed the risk directly, stating it had "information to suggest that exploitation of CVE-2026-59310 has occurred in the wild." That is about as unambiguous a signal as a vendor gives — this is not a low-probability advisory footnote, it is a confirmed, live attack path.
The vulnerability, in plain terms
CVE-2026-59310 carries a CVSS score of 9.8 — as close to maximum severity as the scale allows. Broadcom released a fix on 29 July 2026. That fix is now fully shipped; there is no ambiguity about patch availability, and any lingering description of the flaw as 'newly patched' understates the current reality: the patch has been out for weeks and is being actively bypassed on unpatched systems.
Adding to the pressure, one compromised vCenter Server Appliance was found targeted by both CVE-2026-59310 and a second flaw, CVE-2026-59309, an authentication-bypass vulnerability that is also seeing active scanning activity. Where both weaknesses exist on the same appliance, an attacker effectively has two independent routes into the management plane.
How fast attackers moved after disclosure
QUIRSO's telemetry shows compromised systems first contacted attacker-controlled infrastructure on 3 August 2026 — described as just five days after the flaw's public disclosure. That turnaround is the real lesson for UK buyers: patch cycles measured in weeks are no longer fast enough for internet-facing management infrastructure of this criticality.
Once inside, the actor has been observed deploying a backdoor alongside reverse_ssh binaries to establish persistence and maintain remote access, a detail independently confirmed by BleepingComputer's reporting on the same campaign. This isn't opportunistic defacement — it's infrastructure built for long-term footholds inside virtualisation environments.

Scale: this is a global sweep, not a targeted hit
QUIRSO's data puts the observed footprint at 361 unique victim IP addresses spread across 47 countries. Germany leads with 55 affected addresses, followed by the United States (41), Turkey (38), Iran (26) and France (25). The UK is not called out separately in the disclosed figures, but a campaign spanning this many countries and this volume of victim infrastructure should be treated as a mass-exploitation event rather than a narrow, geographically confined incident.
That scale matters for prioritisation. Attackers running automated exploitation at this breadth are typically scanning broadly and compromising whatever exposed, unpatched vCenter instances they find — meaning exposure, not sector or size, is the deciding factor in whether an organisation gets hit.
Who's behind it — and why attribution is still soft
QUIRSO assessed with moderate confidence that the campaign is being run by a Chinese-speaking threat actor likely operating in the UTC+08:00 timezone. That is a meaningful signal, not a confirmed attribution to a named group — public reporting across QUIRSO, Broadcom, The Hacker News and BleepingComputer agrees on the technical facts (CVE-2026-59310, CVSS 9.8, active exploitation) but the precise intrusion set identity remains unresolved.
For defenders, the attribution nuance matters less than the behaviour: this actor profile is consistent with patterns seen in prior China-linked campaigns against VMware infrastructure, where virtualisation layers are targeted specifically because compromising the hypervisor management plane gives access to everything running on top of it.
What UK infrastructure teams should do this week
The immediate action is unambiguous: confirm the July patch for CVE-2026-59310 is applied across every vCenter Server Appliance in the estate, and check exposure to CVE-2026-59309 on the same systems given the observed dual-exploitation. If vCenter management interfaces are reachable from the internet or from broad internal segments without strict access controls, that exposure needs closing regardless of patch status.
Beyond patching, teams should hunt specifically for reverse_ssh artefacts and unexpected outbound connections from vCenter appliances, since that is the documented persistence mechanism in this campaign. Organisations without in-house threat-hunting capacity should look at managed detection & response to get eyes on this pattern quickly, and should develop a strong incident response plan specifically covering hypervisor-layer compromise scenarios, which behave very differently from endpoint incidents.
Longer term, this campaign is another data point for organisations weighing their platform roadmap. Repeated critical, actively-exploited vCenter vulnerabilities are a legitimate input into decisions to navigate VMware after Broadcom's acquisition, whether that means tightening operational discipline around the existing estate or reassessing the platform altogether via a look at the best VMware alternatives and a realistic calculation of migration costs. Either way, teams should keep a close eye on Broadcom's advisory cadence and stay informed on Broadcom VMware patches as this campaign continues to develop.
- 01The Hacker News — Suspected China-nexus actor exploits VMware vCenter · 17 August 2026
- 02The Hacker News — Attackers exploit VMware vCenter · 1 August 2026
- 03The Hacker News — Weekly recap: VMware exploits, Windows 0-day · 10 August 2026
- 04The Hacker News — Critical macOS, SharePoint, vCenter flaws · 5 August 2026
- 05The Hacker News — Three critical VMware flaws allow auth bypass · 29 July 2026
- 06BleepingComputer — Critical VMware vCenter RCE flaw exploited for reverse SSH access · 13 August 2026
