A critical vulnerability in VMware’s vCenter software has been exploited by a single threat actor on a global scale, just days after public disclosure. The flaw, known as CVE-2026–59310, allows an attacker with network access to remotely execute arbitrary code within a virtual environment, putting thousands of organizations at risk.
The attack, which was discovered by German incident-response firm QUIRSO, has already compromised systems in 47 countries, with the US, France, Iran, and Turkey being among the most heavily targeted nations. QUIRSO’s Threat Research team identified 361 unique IP addresses impacted by the threat campaign, although it’s unclear how many of these represent actual victims.
The vulnerability was disclosed on July 29, but exploitation began just a few days later, on August 3. According to QUIRSO’s chief operations officer and co-founder, Denis Szadkowski, patching the flaw may not be enough to fully mitigate the threat. The attacker is using an open-source tool called reverse_ssh to create outbound control channels from compromised systems, allowing them to maintain persistence even after the software is updated.
“This is essentially a race between exploitation and patching,” Szadkowski explained in an interview with Dark Reading. “We therefore recommend a forensic investigation of potentially affected systems to rule out an existing compromise.” QUIRSO has published a YARA rule for identifying reverse_ssh builds, urging organizations to review their vCenter instances for signs of compromise.
The rapid pace at which the attack unfolded highlights the challenges faced by heavily targeted vendors like VMware. With attackers able to develop exploits within just five days of public disclosure, organizations must be prepared to respond quickly and effectively to minimize damage.
Szadkowski noted that the small window between disclosure and exploitation doesn’t necessarily indicate the attacker has in-depth knowledge of VMware or similar attacks. “Skilled vulnerability researchers and advanced actors commonly perform patch diffing after disclosure,” he said. “We believe it’s reasonable that a sufficiently skilled researcher could analyze the patch and develop an exploit within this timeframe.”
The situation serves as a reminder to organizations to remain vigilant, even after patching vulnerabilities. As Matt Snyder, principal engineer and detection and response lead at Aviatrix, pointed out, threat actors can use a variety of tools and techniques to maintain persistence in compromised systems.
To protect themselves from this type of attack, organizations should consider implementing additional security measures beyond just patching the vulnerability. This includes conducting thorough forensic investigations of potentially affected systems, monitoring for signs of compromise, and staying up-to-date with the latest threat intelligence. By taking proactive steps to stay ahead of attackers, organizations can minimize their risk and prevent costly breaches.
Source: Dark Reading — 2026-08-13