361 victim IP addresses across 47 countries: that is the tally Quirso reported after detecting exploitation of CVE-2026-59310 within days of Broadcom’s advisory, a burst of activity that turned a vCenter logging service into a route into operating systems worldwide.
CVE-2026-59310: a critical vCenter Syslog directory traversal
The flaw at the center of the campaign is CVE-2026-59310, a critical directory traversal vulnerability in the vCenter Syslog server given a CVSS score of 9.8. Broadcom’s advisory says an unauthenticated attacker with network access to vCenter can exploit the bug to execute arbitrary code, effectively converting a service designed to collect logs into a path into the underlying operating system.
Quirso’s incident response timeline and scale
The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10. Broadcom published the initial advisory on July 29 and, in an accompanying FAQ, said it had not observed exploitation at that time. Broadcom revised the advisory on August 3 to add express patches for 8.0 U2f.
Quirso reported the first compromised systems contacting attacker infrastructure on August 3. The following day produced 151 additional victim IP addresses, and by August 5 roughly 95% of the 361 total Quirso counted had appeared. Germany, the United States, Turkey, Iran and France accounted for 185 of those IPs. Quirso cautioned that an IP address does not necessarily correspond to a single organization, and the company assessed a suspected advanced persistent threat (APT) actor was responsible.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageReverse_ssh persistence and the outbound shell technique
For persistence the actor deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing. Because it “dials outward rather than accepting inbound connections,” Quirso noted, the tool can bypass controls designed to block unsolicited inbound access. Quirso also stressed that presence of the tool alone is not proof of compromise, but the framework’s outbound model is central to how the actor maintained access after initial exploitation.
Fixed releases, no workaround, and Broadcom’s advisory updates
Broadcom has not published a workaround for the flaws. Fixed vCenter releases listed in the advisory are 9.1.0.0300, 9.0.2.0100, and either 8.0 U3k or 8.0 U2f depending on the deployed branch. Broadcom’s fixes address both of the critical vCenter issues called out in the advisory: the exploited directory traversal (CVE-2026-59310) and a separate authentication bypass in VMware Directory Service.
What this means for technologists, affected enterprises, and adversaries
- Technologists and security teams — Patch and evict. As Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo, put it: “There are therefore two clocks to manage,” he said, one for closing the vulnerability and one for evicting anyone who entered before the patch. Applying the fixed releases addresses the vulnerability, but removing established outbound shells and other footholds is a separate remediation task.
- Affected enterprises and procurement leaders — Verify exposure and correlation. Quirso’s count of 361 victim IPs across 47 countries, with concentrated appearances in Germany, the United States, Turkey, Iran and France, underscores the geographic spread defenders must check. Organizations should treat the advisory dates and Quirso’s observed timeline (first attacker contacts on August 3, broad activity by August 5) as the window when exploitation accelerated.
- Adversaries and threat actors — Rapid exploitation around disclosure. Quirso said the strong correlation between Broadcom’s advisory and the spike in exploitation points to the advisory as the campaign’s starting point. The incident illustrates how public disclosure can coincide with very fast abuse by actors prepared to weaponize a newly published flaw.
The record in this episode is stark: within days of Broadcom’s July 29 advisory, active exploitation using an open-source reverse shell was observed, and by the first week of August hundreds of IP addresses were calling attacker infrastructure. Fixed releases exist, but Broadcom has not published a workaround, and defenders face distinct tasks—closing the engineering hole and evicting any intruders who slipped in before patches were applied. Quirso’s August 10 publication provides the data points; the practical work for each affected environment has just begun.
Source: Infosecurity Magazine — vCenter Flaw Exploited Just Five Days After Disclosure



