Global Threat Campaign Hits Critical VMware vCenter Flaw
A single threat actor has been aggressively exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, initiating a global threat campaign that began shortly after public disclosure. The vulnerability, a directory traversal flaw, allows remote code execution, and QUIRSO’s research indicates exploitation activity spanned 47 countries, with the US, France, Iran, and Turkey being heavily targeted. Despite patching efforts, the threat actor is establishing post-exploitation persistence using reverse_ssh, highlighting a significant challenge for organizations due to the short window between disclosure and active exploitation and the complexity of patching virtual environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
