Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

August 12, 2026 2 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations utilizing VMware vCenter
Incident: Active exploitation of a critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter.
Impact: Full system compromise and persistent remote access to critical virtualization infrastructure.
Attacker: Suspected Advanced Persistent Threat (APT) actor
Analysis: Threat actors are actively exploiting CVE-2026-59310 to achieve remote code execution on vCenter servers. Once inside, they deploy malicious cron jobs and the reverse_ssh tool to bypass perimeter defenses and maintain persistent access. The campaign has already impacted hundreds of targets globally, indicating a coordinated effort by a suspected APT.
Recommendations: Immediately apply Broadcom’s latest security patches for VMware vCenter; Audit vCenter hosts for unauthorized cron jobs or unexpected scheduled tasks; Monitor for suspicious outbound SSH connections to unknown external domains
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-17 10:55 UTC

Exploitation of critical VMware vCenter vulnerabilities to deploy Babuk-derived ransomware. Full administrative root access to virtualized infrastructure and potential widespread data encryption. Threat actors are exploiting CVE-2026-59310 to achieve immediate non-interactive root code execution on vCenter Server Appliances. The campaign leverages both directory traversal and authentication bypass flaws to compromise infrastructure across 47 countries. The use of Babuk-derived ransomware indicates a high-impact objective focusing on critical infrastructure disruption.

Corroborating source: thehackernews.com

Update — 2026-08-17 13:59 UTC

Multiple critical vulnerabilities in VMware, Windows, and macOS were actively exploited by APTs and cybercriminals. Full system compromise, root access, and deployment of ransomware or crypto-miners. Threat actors are increasingly leveraging critical directory-traversal and authentication flaws to gain root access across diverse platforms. Notably, ransomware is being deployed as a diversionary tactic to mask deeper espionage efforts within compromised vCenter servers. The simultaneous exploitation of macOS and Windows zero-days indicates a highly active period for both state-sponsored and opportunistic actors.

Corroborating source: thehackernews.com

Leave a Reply

Your email address will not be published. Required fields are marked *