CARDS
CARDS
BleepingComputer reports that QUIRSO observed exploitation of VMware vCenter CVE-2026-59310 beginning August 3, 2026. By August 7, QUIRSO reportedly identified 361 compromised IP addresses across 47 countries and deployment of reverse_ssh for outbound persistent access. Broadcom confirms the critical unauthenticated RCE but has not publicly confirmed these campaign details; CISA had not added the CVE to KEV as of August 16.
Last updated Aug 16, 2026, 4:00 PM EDT
Evidence Boundary
Bottom Line Up Front
BleepingComputer reports that QUIRSO observed exploitation of VMware vCenter CVE-2026-59310 beginning August 3, 2026. By August 7, QUIRSO reportedly identified 361 compromised IP addresses across 47 countries and deployment of reverse_ssh for outbound persistent access. Broadcom confirms the critical unauthenticated RCE but has not publicly confirmed these campaign details; CISA had not added the CVE to KEV as of August 16.[1][2][3]
Potential arbitrary code execution and persistent outbound remote access in the centralized control plane for ESXi hosts and virtual machines. Local consequences may include identity, workload, network, storage, snapshot, backup, and availability impact, but no public victim-level impact matrix is retained.[1][2][3]
Patch to the fixed vCenter release, restrict management reachability and egress, preserve the vulnerable interval, hunt unexpected outbound SSH and reverse_ssh-like artifacts, review accounts, roles, tasks and configuration, and assess hosts, VMs, snapshots, datastores, networks, backups, and connected administrative trust.[1][2][3]
Decision Summary
BleepingComputer reports that QUIRSO observed exploitation of VMware vCenter CVE-2026-59310 beginning August 3, 2026. By August 7, QUIRSO reportedly identified 361 compromised IP addresses across 47 countries and deployment of reverse_ssh for outbound persistent access. Broadcom confirms the critical unauthenticated RCE but has not publicly confirmed these campaign details; CISA had not added the CVE to KEV as of August 16.
The retained record scopes this as unauthenticated virtualization-management-plane exploitation and persistent remote access activity during Observed from August 3, 2026; public reporting through August 13, 2026. Potential arbitrary code execution and persistent outbound remote access in the centralized control plane for ESXi hosts and virtual machines. Local consequences may include identity, workload, network, storage, snapshot, backup, and availability impact, but no public victim-level impact matrix is retained.[1][2][3]
Patch to the fixed vCenter release, restrict management reachability and egress, preserve the vulnerable interval, hunt unexpected outbound SSH and reverse_ssh-like artifacts, review accounts, roles, tasks and configuration, and assess hosts, VMs, snapshots, datastores, networks, backups, and connected administrative trust.[1][2][3]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for Broadcom's vulnerability, severity, access, fixed-version, and no-workaround facts. Moderate for campaign scale, start date, geography, and reverse_ssh behavior because they are attributed to QUIRSO through independent reporting rather than a retained primary QUIRSO publication or Broadcom confirmation..[1][2][3]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Campaign Chronology
29 Jul 2026
VMSA-2026-0006 identifies the critical vCenter Syslog RCE and no workaround.[1]
3 Aug 2026
7 Aug 2026
QUIRSO reportedly observes reverse_ssh deployment and international spread.[2]
13 Aug 2026
BleepingComputer publishes the QUIRSO findings; Broadcom confirmation remains absent.[2]
16 Aug 2026
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
A compromised IP count is not an organization count. No named victim, reliable actor identity, ransomware link, or public complete IOC set is retained. Internet exposure is not required if another foothold can reach the management network, and internal placement alone does not prove isolation.
Evidence Controls
IntelliOS
Citations