VMware vCenter Vulnerability

Overview

Threat actors are actively exploiting CVE‑2026‑59310, a critical directory‑traversal vulnerability in VMware vCenter Server (CVSS 9.8). According to German cybersecurity firm QUIRSO, attackers are leveraging the flaw to execute arbitrary code and establish persistent remote access using malicious cron jobs and the open‑source tool reverse_ssh.

Attack Chain

  • Initial access: Exploitation of CVE‑2026‑59310 enables arbitrary code execution.
  • Persistence: Attackers deploy cron jobs configured with reverse_ssh to maintain outbound connections to attacker‑controlled infrastructure.
  • Victim scope: 361 unique IPs across 47 countries, with concentrations in Germany, the U.S., Turkey, Iran, and France.
  • Timing: Exploitation began on August 3, just five days after Broadcom publicly disclosed the flaw.

Attribution and Context

  • QUIRSO suspects involvement of an advanced persistent threat (APT) actor, though attribution remains unclear.
  • VMware appliances have historically been lucrative targets for Chinese threat groups like UNC5174, who weaponized vCenter flaws in espionage campaigns.
  • Similar techniques were observed in PurpleHaze operations (April 2025), where reverse_ssh was used to establish covert outbound connections.

Why Reverse_SSH Matters

  • Outbound connections: Reverse_ssh allows attackers to bypass inbound firewall restrictions by initiating connections from the compromised host.
  • Not always malicious: QUIRSO cautions that reverse_ssh alone is not proof of compromise. However, its presence alongside unauthorized installations and unexpected outbound traffic on vulnerable vCenter appliances is a high‑priority indicator.

Related Activity

  • CVE‑2026‑59309: Defused Cyber observed increased scanning activity targeting another critical vCenter flaw (unauthenticated auth‑bypass in vmdir).
  • QUIRSO notes no confirmed correlation between CVE‑2026‑59309 scanning and CVE‑2026‑59310 exploitation, but warns of overlapping attacker interest.

Defensive Guidance

Organizations should:

  • Patch immediately: Apply Broadcom’s fixes released last month.
  • Monitor outbound traffic: Investigate reverse_ssh activity and unexpected cron jobs.
  • Harden VMware appliances: Restrict network exposure and enforce least‑privilege access.
  • Deploy intrusion detection: Watch for scanning patterns against /sdk/ and /websso endpoints.
  • Conduct forensic reviews: Validate whether exploitation attempts resulted in persistent compromise.

Expert in the Cloud Insight

The exploitation of CVE‑2026‑59310 underscores how rapid disclosure-to-exploitation cycles are shrinking. Attackers weaponized the flaw within days, highlighting the urgency of patch velocity and outbound traffic monitoring. Reverse_ssh persistence is a reminder that attackers increasingly rely on decentralized, outbound‑driven infrastructure to evade detection. For defenders, the lesson is clear: patch fast, monitor deeper, and treat VMware appliances as high‑value targets.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.