Following a critical security advisory from Broadcom in late July 2026, security researchers are observing widespread, automated scanning activity targeting VMware vCenter Server instances. The scans are aimed at identifying systems vulnerable to several critical flaws, most notably CVE-2026-59309, a CVSS 9.8 authentication bypass. This fingerprinting activity is a strong precursor to mass exploitation. Meanwhile, a separate critical vulnerability from the same advisory, CVE-2026-59310 (CVSS 9.8), is already confirmed to be under active exploitation in the wild to establish persistent remote access on compromised systems. Administrators are urged to patch their vSphere environments immediately and ensure management interfaces are not exposed to the internet.
The VMSA-2026-0006 advisory detailed several flaws, with three being of critical concern:
CVE-2026-59309: Authentication Bypass in vmdir (CVSS 9.8)
CVE-2026-59310: Directory Traversal in Syslog Server (CVSS 9.8)
CVE-2026-47876: Out-of-Bounds Write in VMXNET3 (CVSS 9.3)
/sdk/ and /websso to identify vulnerable instances of CVE-2026-59309.cron job, which then establishes a persistent reverse SSH tunnel using the reverse_ssh tool. This campaign has already compromised over 360 unique IP addresses globally.Compromise of a vCenter Server is a worst-case scenario for most organizations. It grants an attacker centralized control over the entire virtualized environment. An attacker could exfiltrate, modify, or destroy virtual machines and their data; deploy ransomware across the entire estate; or use the hypervisor as a persistent and hard-to-detect launchpad for further attacks within the network. The active scanning indicates that automated, widespread attacks are likely imminent, potentially leading to a wave of breaches and ransomware incidents similar to past events involving critical flaws in virtualization management platforms.
The following patterns may help identify vulnerable or compromised systems:
/sdk//webssoreverse_sshcronOutbound SSH/sdk/ and /websso endpoints from single IP addresses, which can indicate scanning./etc/cron.d/. Alert on the appearance of unexpected binaries like reverse_ssh.APT group actively exploiting CVE-2026-59310 in VMware vCenter, compromising 361 systems across 47 countries just five days post-patch.
Apply the patches from VMSA-2026-0006 to all affected VMware products.
Mapped D3FEND Techniques:
Do not expose vCenter management interfaces to the internet. Restrict access to a secure, internal management network.
Mapped D3FEND Techniques:
Use firewalls to block anomalous outbound traffic, such as SSH from a vCenter appliance.
Mapped D3FEND Techniques:
The most urgent action is to apply the security patches detailed in Broadcom's VMSA-2026-0006 advisory. Given the active exploitation of CVE-2026-59310 and widespread scanning for CVE-2026-59309, patching cannot be delayed. This should be treated as an emergency change. Prioritize all internet-facing or otherwise exposed vCenter Server instances. Use vSphere Lifecycle Manager to streamline the update process across your ESXi hosts and vCenter. Verifying the patch level of all components post-update is crucial to ensure the vulnerabilities are fully remediated.
Immediately audit the network exposure of all vCenter Server management interfaces. Under no circumstances should these interfaces be accessible from the public internet. Implement strict firewall rules to ensure vCenter is only accessible from a segregated, secure management network (a 'management VLAN'). Access to this management network should require connecting through a bastion host or a VPN with multi-factor authentication. This single control dramatically reduces the attack surface and would have prevented both the scanning and the exploitation attempts described.
As a critical defense-in-depth measure, implement egress filtering on the network segment containing your vCenter Server. A vCenter appliance has no legitimate reason to initiate an outbound SSH connection to the internet. Create a default-deny firewall rule for outbound traffic from the vCenter appliance, only allowing specific, required connections (e.g., to NTP servers, VMware update servers). A specific rule to block outbound TCP port 22 (SSH) would have defeated the persistence mechanism used in the active exploitation of CVE-2026-59310. This control helps contain a compromised system and provides a high-fidelity alert if an attacker attempts to establish a C2 channel.
Broadcom releases VMSA-2026-0006 security advisory.
Systems compromised via CVE-2026-59310 begin communicating with attacker infrastructure.
Widespread scanning activity for vCenter vulnerabilities is reported by researchers.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.