vulnerability
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
High
Summary
Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP addresses across 47 countries, primarily in Germany, the U.S., Turkey, Iran, and France. The campaign involved a successful compromise, with evidence strongly suggesting CVE-2026-59310 as the initial access vector, and a correlation with previous VMware exploitation campaigns by Chinese APT actors.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
