CVE-2026-59310 Exploitation Hits 340+ IPs Three Days After Patch
Post-disclosure exploitation of CVE-2026-59310 began within days, confirming public advisories as exploitation triggers. Evidence shows mass scanning of exposed vCenter followed by reverse_ssh persistence. Unpatched public instances remain high-value targets for follow-on operations.
Broadcom disclosed the CVSS 9.8 flaw July 29 alongside four other VMware issues. Quirso telemetry shows public-facing vCenter instances scanned and compromised within 72 hours, with attackers using network-accessible Syslog paths for arbitrary code execution before dropping the open-source reverse_ssh framework to establish outbound C2.
IP distribution concentrates in Germany, the US, Turkey, Iran and France, though many addresses route through hosting providers and cloud tenants, preventing direct victim attribution. The rapid timeline and correlation with disclosure date indicate weaponization from the advisory rather than prior zero-day knowledge.
Technical evidence consists of YARA-detectable reverse_ssh binaries and anomalous outbound SSH connections from vCenter hosts. No independent attribution to a named APT exists beyond Quirso’s generic label; official Broadcom statements note only the RCE vector without confirming active campaigns.
Organizations must audit exposed vCenter instances for unauthorized binaries and unexpected outbound ports, as the pattern matches prior rapid post-disclosure exploitation of management interfaces.
Quirso: 150+ additional victim IPs will appear in public scans by August 20 if exposed vCenter count exceeds 2,000.
Sources (2)
- [1]Broadcom VMware Security Advisory(https://www.broadcom.com/support/vmware-security-advisories)
- [2]Quirso Incident Report(https://www.quirso.com/vcenter-exploitation-analysis)