Published Security3 min read
vCenter's Patch Window Is Five Days: CVE-2026-59310 Hit 361 IPs Across 47 Countries
Broadcom's July 29 advisory looks like the starting gun. By August 3 compromised hosts were calling attacker infrastructure, and roughly 95% of victims had appeared within a week.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A critical-severity VMware vCenter vulnerability was exploited within five days of disclosure by Broadcom.
- The threat research team at German digital forensics firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.
- CVE-2026-59310 is a critical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.
- Broadcom said an unauthenticated attacker with network access to vCenter can exploit the flaw to execute arbitrary code, turning a service built to collect logs into a route into the operating system.
- Broadcom published its advisory relating to the flaw on July 29.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A critical directory traversal flaw in the VMware vCenter Syslog server, CVE-2026-59310, was being exploited five days after Broadcom disclosed it, according to research published on August 10 by the German digital forensics firm Quirso [1][2][9]. Quirso counted 361 victim IP addresses across 47 countries, which puts a number on something operators have suspected for a while: the management plane of a virtualisation estate no longer gets a maintenance window measured in weeks [10].
The mechanics are unglamorous and that is the point. Broadcom rated the flaw CVSS 9.8 and said an unauthenticated attacker with network access to vCenter can use it to execute arbitrary code, which converts a service whose job is collecting logs into a path into the underlying operating system [3][4].
The timeline is the story. Broadcom published its advisory on July 29 and stated in an accompanying FAQ that it had not observed exploitation [5][6]. It revised the advisory on August 3 to add 8.0 U2f express patches [7]. Quirso says it first saw compromised systems contacting attacker infrastructure that same day, five days after the advisory [8][20]. August 4 brought 151 further victim IPs, and by August 5 roughly 95% of the 361 total had appeared, or about 343 addresses inside a week of disclosure [11][12][21]. Germany, the United States, Turkey, Iran and France accounted for 185 of the victim IPs, slightly more than half the total [13][22].
Quirso attributes the campaign to a suspected advanced persistent threat actor and allows that the attacker may have had prior knowledge of the flaw, but says the strong correlation between disclosure and exploitation points to the advisory itself as the campaign's starting point [14][15]. The firm also cautions that one IP address does not necessarily map to one organisation, so 361 is a floor for infrastructure and an unknown for victim organisations [10].
For persistence the actor deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing [16]. Because it dials outward rather than listening for inbound connections, it can walk past controls designed to block unsolicited inbound access, and Quirso stresses that finding it on a host is not by itself proof of compromise [17][18].
Jason Soroko, senior fellow at the certificate lifecycle management vendor Sectigo, said patching alone will not resolve the incident. "There are therefore two clocks to manage," he said: one for closing the vulnerability and one for evicting anyone who got in before the patch [19].
There is no published workaround from Broadcom [23]. The fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the deployed branch, and they cover both critical vCenter flaws in the advisory: the exploited directory traversal and an authentication bypass in VMware Directory Service [24][25].
What to watch: whether the authentication bypass in VMware Directory Service draws the same attention as the traversal, since it shipped in the same advisory and carries the same disclosure clock [25]. Watch also for confirmation of how many of the 361 addresses correspond to distinct organisations [10], and for hunting guidance that separates legitimate reverse_ssh use from the campaign's, because the tool is dual use and outbound-only [16][17][18].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A critical-severity VMware vCenter vulnerability was exploited within five days of disclosure by Broadcom.
ReportedView cited source - [2]
The threat research team at German digital forensics firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.
ReportedView cited source - [3]
CVE-2026-59310 is a critical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.
ReportedView cited source - [4]
Broadcom said an unauthenticated attacker with network access to vCenter can exploit the flaw to execute arbitrary code, turning a service built to collect logs into a route into the operating system.
- [6]
In an FAQ accompanying the advisory, Broadcom stated it had not observed exploitation.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 13vCenter Flaw Exploited Just Five Days After Disclosure
Additional citations
- Broadcom
- Quirso
- Jason Soroko, Sectigo



