vCenter CVE-2026-59310 Active Exploitation
A critical unauthenticated management-plane RCE: when it is initial access, what is actually observed, and why patching must be paired with investigation
- Field
- User Topic
- Value
- VMware vCenter CVE-2026-59310 and reported exploitation
- Field
- Interpreted Questions
- Value
- Decision question: must an owner treat a reachable, previously vulnerable vCenter as an exposure only or as a suspected compromise? Supporting questions cover initial-access conditions, the difference between vendor-confirmed vulnerability facts and QUIRSO-observed activity, fixed builds, KEV and victim status, exact public detection content, unavailable IOC categories, evidence preservation, recovery, and whether campaign or actor CARDS are justified.
- Field
- Initial Observations
- Value
- Broadcom confirms a CVSS 9.8 unauthenticated directory-traversal flaw in the vCenter Syslog server, arbitrary-code-execution impact, fixed releases, and no workaround. Broadcom published because Atredis researchers privately reported the defect—not because the advisory announced an incident. QUIRSO later reported connections from compromised systems beginning August 3, 361 victim IP addresses across 47 countries by August 7, and deployment of the dual-use NHAS reverse_ssh client. QUIRSO published a generic YARA rule but withheld campaign infrastructure during law-enforcement coordination. CISA KEV listing, named victims, Broadcom confirmation of the campaign, and supported actor attribution remained absent at the cutoff.1, 5, 6, 11, 12
- Field
- Source Coverage
- Value
- Tier
- Tier 0 — canonical registries
- Checked
- 5
- Candidate Hits
- 4
- Planner Selected
- 5
- Not Used
- 0
- Tier
- Tier 1 — vendor / primary
- Checked
- 4
- Candidate Hits
- 4
- Planner Selected
- 4
- Not Used
- 0
- Tier
- Tier 2 — specialist research
- Checked
- 4
- Candidate Hits
- 3
- Planner Selected
- 3
- Not Used
- 1
- Tier
- Tier 3 — independent security news
- Checked
- 4
- Candidate Hits
- 2
- Planner Selected
- 1
- Not Used
- 3
- Tier
- Tier 4 — community signal
- Checked
- 3
- Candidate Hits
- 2
- Planner Selected
- 0
- Not Used
- 3
- Tier
- Tier 5 — custom sources
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tier 6 — private integrations
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tier 7 — inner discovery
- Checked
- 5
- Candidate Hits
- 5
- Planner Selected
- 5
- Not Used
- 0
- Tier
- Tier 8 — expansion research
- Checked
- 6
- Candidate Hits
- 4
- Planner Selected
- 3
- Not Used
- 3
- Tier
- Total
- Checked
- 31
- Candidate Hits
- 25
- Planner Selected
- 17
- Not Used
- 14
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 — canonical registries 5 4 5 0 Tier 1 — vendor / primary 4 4 4 0 Tier 2 — specialist research 4 3 3 1 Tier 3 — independent security news 4 2 1 3 Tier 4 — community signal 3 2 0 3 Tier 5 — custom sources 0 0 0 0 Tier 6 — private integrations 0 0 0 0 Tier 7 — inner discovery 5 5 5 0 Tier 8 — expansion research 6 4 3 3 Total 31 25 17 14
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | VMware vCenter CVE-2026-59310 and reported exploitation | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | Decision question: must an owner treat a reachable, previously vulnerable vCenter as an exposure only or as a suspected compromise? Supporting questions cover initial-access conditions, the difference between vendor-confirmed vulnerability facts and QUIRSO-observed activity, fixed builds, KEV and victim status, exact public detection content, unavailable IOC categories, evidence preservation, recovery, and whether campaign or actor CARDS are justified. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Broadcom confirms a CVSS 9.8 unauthenticated directory-traversal flaw in the vCenter Syslog server, arbitrary-code-execution impact, fixed releases, and no workaround. Broadcom published because Atredis researchers privately reported the defect—not because the advisory announced an incident. QUIRSO later reported connections from compromised systems beginning August 3, 361 victim IP addresses across 47 countries by August 7, and deployment of the dual-use NHAS reverse_ssh client. QUIRSO published a generic YARA rule but withheld campaign infrastructure during law-enforcement coordination. CISA KEV listing, named victims, Broadcom confirmation of the campaign, and supported actor attribution remained absent at the cutoff.1, 5, 6, 11, 12 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
The decisive distinction is not simply patched versus unpatched. Owners must know whether the vulnerable service was reachable, whether evidence covers that interval, and whether any persistent access or management-plane action occurred.1, 5, 6
Severity
9.8 Critical
VMware CNA CVSS 3.1; NVD awaiting enrichment.
Reported compromised IPs
361
QUIRSO count by August 7; not a named-organization count.
Reported countries
47
Source-bounded geographic spread.
CISA KEV
Not listed
Checked August 16, 2026.
- Decision Point
- How serious is the flaw?
- Current Evidence
- CVSS 9.8 Critical unauthenticated path traversal in the vCenter Syslog server can lead to arbitrary code execution.
- Required Action
- Use the vendor matrix to identify every affected branch and fixed build.
- Decision Point
- Can it provide initial access?
- Current Evidence
- Yes when the vulnerable service is reachable from the attacker. No vCenter account or user interaction is required.
- Required Action
- Remove public exposure and restrict all management-plane paths to explicitly trusted sources.
- Decision Point
- Is exploitation real or theoretical?
- Current Evidence
- QUIRSO reports compromised-system callbacks beginning August 3 and 361 victim IPs across 47 countries by August 7.
- Required Action
- Treat reachable pre-fix systems as investigation candidates, not patch-only tickets.
- Decision Point
- What happened after access?
- Current Evidence
- QUIRSO reports deployment of the dual-use NHAS reverse_ssh client for continuing outbound remote access.
- Required Action
- Hunt appliance artifacts and unexplained outbound control traffic; validate any tool match in context.
- Decision Point
- Are campaign IOCs public?
- Current Evidence
- No campaign-specific attacker IPs, domains, URLs, filenames, or hashes were retained; QUIRSO says infrastructure was withheld during law-enforcement coordination.
- Required Action
- Use the published generic YARA rule plus network, file, process, service, identity, and task/event evidence.
- Decision Point
- Does patching close the incident?
- Current Evidence
- Fixed builds close the known vulnerable path; Broadcom provides no workaround.
- Required Action
- Patch, preserve evidence, assess the vulnerable interval, rotate exposed trust, and rebuild if appliance integrity cannot be established.
- Decision Point
- Who is responsible?
- Current Evidence
- The campaign is unattributed. An advanced-actor characterization is not supported by public evidence sufficient for a named actor.
- Required Action
- Track the behavior as an unattributed vCenter reverse-SSH exploitation campaign.
| Decision Point | Current Evidence | Required Action | Evidence Boundary |
|---|---|---|---|
| How serious is the flaw? | CVSS 9.8 Critical unauthenticated path traversal in the vCenter Syslog server can lead to arbitrary code execution. | Use the vendor matrix to identify every affected branch and fixed build. | Severity describes technical impact; it does not prove local exposure or compromise.1, 3 |
| Can it provide initial access? | Yes when the vulnerable service is reachable from the attacker. No vCenter account or user interaction is required. | Remove public exposure and restrict all management-plane paths to explicitly trusted sources. | An internally restricted service generally requires a prior foothold with a route to the management network.1, 3 |
| Is exploitation real or theoretical? | QUIRSO reports compromised-system callbacks beginning August 3 and 361 victim IPs across 47 countries by August 7. | Treat reachable pre-fix systems as investigation candidates, not patch-only tickets. | Broadcom and CISA had not publicly confirmed the campaign at the August 16 cutoff.5, 11 |
| What happened after access? | QUIRSO reports deployment of the dual-use NHAS reverse_ssh client for continuing outbound remote access. | Hunt appliance artifacts and unexplained outbound control traffic; validate any tool match in context. | Public reporting does not disclose the exact persistence mechanism or prove identical activity on every victim IP.11, 12, 13 |
| Are campaign IOCs public? | No campaign-specific attacker IPs, domains, URLs, filenames, or hashes were retained; QUIRSO says infrastructure was withheld during law-enforcement coordination. | Use the published generic YARA rule plus network, file, process, service, identity, and task/event evidence. | The YARA rule detects standard reverse_ssh clients and is not a CVE exploit signature.11, 12 |
| Does patching close the incident? | Fixed builds close the known vulnerable path; Broadcom provides no workaround. | Patch, preserve evidence, assess the vulnerable interval, rotate exposed trust, and rebuild if appliance integrity cannot be established. | A fixed version does not remove access established before remediation or prove the system was never exploited.1, 14, 15, 16 |
| Who is responsible? | The campaign is unattributed. An advanced-actor characterization is not supported by public evidence sufficient for a named actor. | Track the behavior as an unattributed vCenter reverse-SSH exploitation campaign. | Do not infer ransomware, nation-state sponsorship, or a named group from victim scale or tool choice.6, 11 |
vCenter is not simply another server. Administrators use it to coordinate virtualization hosts, workloads, permissions, networks, storage, snapshots, migrations, and automation. A compromise can place many business systems and parts of the recovery plane within one investigation boundary.8
Broadcom disclosed the flaw on July 29 and updated the advisory on August 3. The vCenter Syslog server permits path traversal leading to arbitrary code execution for an attacker with network access. The CNA vector requires no privileges or user interaction, and Broadcom lists no workaround.1, 3, 9
The material delta is later exploitation reporting. BleepingComputer says QUIRSO observed activity from August 3, counted 361 compromised IPs across 47 countries by August 7, and identified reverse_ssh deployment. Those claims are operationally important but are not yet public Broadcom or CISA confirmation.2, 5, 6
Each audience needs a different decision from the same evidence. A generic instruction to patch is not enough.
- Audience
- Executive / business owner
- Decision Needed
- Can vCenter compromise disrupt critical services or recovery, and who owns the response?
- Minimum Evidence
- Critical workloads, recovery dependencies, owner, exposure state, patch deadline, investigation status, and material uncertainty.
- Audience
- Infrastructure / virtualization
- Decision Needed
- Which instances and branches are affected, reachable, and ready for supported emergency change?
- Minimum Evidence
- FQDN, appliance identity, exact build, linked-mode membership, VCF/Telco packaging, integrations, backups, reachability, and maintenance plan.
- Audience
- SOC / DFIR
- Decision Needed
- Does evidence support exposure only, suspected compromise, or confirmed unauthorized activity?
- Minimum Evidence
- Network flows, DNS, YARA results, files, services, processes, vCenter logs, tasks/events, identities, SSH keys, and downstream management actions.
- Audience
- MSP / hosting provider
- Decision Needed
- Could one shared administration path create multi-customer concentration?
- Minimum Evidence
- Tenant-by-tenant instance inventory, jump paths, service accounts, remote tools, segmentation, evidence retention, and customer ownership.
- Audience
- Cyber insurer / broker
- Decision Needed
- Is this a vulnerability-management event or a reportable incident with potential loss?
- Minimum Evidence
- Reachability, vulnerable window, actual access evidence, confirmed actions, affected systems, interruption, data impact, containment, and recovery confidence.
- Do Not Assume
- Reported victim IP counts are not insured organization counts or confirmed claims.11
- Audience
- Counsel / communications
- Decision Needed
- What can be stated accurately and what requires local proof?
- Minimum Evidence
- Source chronology, internal findings, named-system scope, data-access evidence, privilege used, persistence, recovery actions, and known unknowns.
| Audience | Decision Needed | Minimum Evidence | Do Not Assume |
|---|---|---|---|
| Executive / business owner | Can vCenter compromise disrupt critical services or recovery, and who owns the response? | Critical workloads, recovery dependencies, owner, exposure state, patch deadline, investigation status, and material uncertainty. | A 9.8 score or reported global activity does not prove this organization was compromised.1, 8, 11 |
| Infrastructure / virtualization | Which instances and branches are affected, reachable, and ready for supported emergency change? | FQDN, appliance identity, exact build, linked-mode membership, VCF/Telco packaging, integrations, backups, reachability, and maintenance plan. | A major-version label such as vCenter 8 is not proof of a fixed build.1, 7, 16 |
| SOC / DFIR | Does evidence support exposure only, suspected compromise, or confirmed unauthorized activity? | Network flows, DNS, YARA results, files, services, processes, vCenter logs, tasks/events, identities, SSH keys, and downstream management actions. | Absence of withheld campaign infrastructure or one negative YARA scan does not establish a clean system.11, 12, 14, 15 |
| MSP / hosting provider | Could one shared administration path create multi-customer concentration? | Tenant-by-tenant instance inventory, jump paths, service accounts, remote tools, segmentation, evidence retention, and customer ownership. | One customer's findings cannot close scope for another customer or shared platform.8, 14 |
| Cyber insurer / broker | Is this a vulnerability-management event or a reportable incident with potential loss? | Reachability, vulnerable window, actual access evidence, confirmed actions, affected systems, interruption, data impact, containment, and recovery confidence. | Reported victim IP counts are not insured organization counts or confirmed claims.11 |
| Counsel / communications | What can be stated accurately and what requires local proof? | Source chronology, internal findings, named-system scope, data-access evidence, privilege used, persistence, recovery actions, and known unknowns. | Do not attribute the operator, name victims, or claim data theft from public campaign reporting alone.5, 6, 11 |
- What it is: A CVSS 9.8 Critical, unauthenticated path-traversal flaw in the vCenter Syslog server that can lead to arbitrary code execution.1, 3, 9
- Initial access: Yes when the service is reachable from the attacker, including direct internet exposure. Internally isolated vCenter requires a prior network foothold; normal login MFA does not neutralize a pre-auth service flaw.1, 3
- Observed activity: QUIRSO reportedly observed exploitation beginning August 3, 361 compromised IPs in 47 countries by August 7, and reverse_ssh deployment for persistent outbound access.6
- Evidence boundary: Broadcom has not publicly confirmed the reported campaign, CISA had not added the CVE to KEV by August 16, and no reliable public source names victim organizations or the actor.2, 5, 6
- Action: Upgrade immediately, restrict vCenter reachability and egress, preserve evidence, and hunt the full vulnerable window. Patching closes the flaw but does not remove established access.1, 6, 7
VMware vCenter is the central control system for a virtualized environment. Administrators use it to manage ESXi hosts, virtual machines, permissions, networks, storage, snapshots, migrations, and automation from one place. That makes it unusually valuable to an attacker: compromising vCenter can expose far more than one server and can place production workloads, privileged administration, and parts of the recovery process inside the same investigation boundary.8
Broadcom published VMSA-2026-0006 on July 29, 2026 after Phil Brass and Matt South of Atredis Partners privately reported a directory-traversal flaw in the vCenter Syslog server. The advisory was a vulnerability disclosure with patches, not an announcement that Broadcom had discovered a customer breach. Broadcom assigned CVE-2026-59310 a 9.8 Critical score because an attacker who can reach the affected service needs no account and no user interaction to execute arbitrary code. Broadcom lists no workaround.1, 2, 3
The phrase remote and unauthenticated does not mean every vCenter is automatically reachable from the public internet. It means the attacker needs a network path to the vulnerable vCenter service but does not need valid vCenter credentials. A publicly reachable system can therefore be an initial-access target. A vCenter restricted to a management network generally requires the attacker to first reach that network through a VPN, partner path, compromised workstation, jump host, monitoring platform, or another internal foothold. MFA on the normal vCenter login does not neutralize a pre-authentication service flaw.1, 3
The story became more urgent after disclosure. QUIRSO reported that compromised systems began connecting to attacker-controlled infrastructure on August 3, five days after the advisory. It counted 151 new victim IP addresses on August 4, 343 by August 5, and 361 across 47 countries by August 7. QUIRSO said the operator deployed the open-source NHAS reverse_ssh framework after access. That is reported evidence of real exploitation and post-exploitation access—not merely a theoretical vulnerability—but the victim unit is an IP address, not a verified organization count.6, 11
Important facts remain unavailable. QUIRSO withheld the campaign IP addresses, domains, and other specific infrastructure while coordinating with law enforcement. No reliable public source retained here identifies a victim organization, publishes a campaign-specific malware hash or filename, or proves data theft, encryption, outage, or a particular business impact. Broadcom had not publicly confirmed QUIRSO's campaign, CISA had not added CVE-2026-59310 to the Known Exploited Vulnerabilities catalog by the August 16 cutoff, and the public record did not support attribution to a named actor.5, 6, 11
The reported reverse_ssh deployment matters because the client initiates an outbound SSH-based control channel. That can give an operator continuing remote access even when inbound administration is tightly restricted. The NHAS project is legitimate dual-use software, so its presence is not automatically malicious. QUIRSO's generic YARA rule detects standard NHAS reverse_ssh client builds by combining Go build metadata, stable source-package paths, and client-configuration strings; a match must be correlated with path, owner, execution time, parent process, network destination, and change authorization.11, 12, 13
Every owner should identify all vCenter instances and exact builds, map every route that could reach them, and move supported systems to the current fixed release: 9.1.0.0300, 9.0.2.0100, 8.0 U3k, 8.0 U2f, or the product-specific VCF or Telco remediation path. Remove direct internet exposure, restrict management access to known administration paths, review outbound connectivity from the appliance, and preserve evidence before making changes that could rotate logs or destroy artifacts. A patch closes the known vulnerable path; it does not prove that earlier exploitation did not occur.1, 7, 14
For systems that were vulnerable and reachable, treat remediation and compromise assessment as separate workstreams. Use the QUIRSO YARA rule as one lead, then review vCenter appliance files and services, outbound connections, vpxd and related logs, tasks and events, identities, roles, SSH keys, logging changes, and unexplained actions involving hosts, virtual machines, snapshots, clones, datastores, networks, or backups. Closure should document the vulnerable interval, reachability, retained telemetry, findings, fixed build, credential or key rotation, recovery decision, and unresolved evidence gaps. If appliance integrity cannot be established, rebuild through a supported recovery path rather than declaring the system clean from patch status alone.12, 14, 15, 16
Research and scoping note
IntelliOS classification: this is a material exploitation delta to a newly disclosed vulnerability. The evidence supports an unattributed vCenter reverse-SSH exploitation campaign CARD and a CVE Watch product. It does not support a named threat-actor CARD, a list of 361 organizations, or a claim that every exposed vCenter was compromised.5, 6, 11, 12
The alert is a delta to the July 29 vulnerability baseline. These rows distinguish what changed from what remains unchanged or unknown.
- Date
- 29 Jul 2026
- Material Delta
- Broadcom disclosed CVE-2026-59310, fixed supported branches, and listed no workaround.
- Effect on Decision
- Created an emergency remediation requirement for affected reachable vCenter systems.
- Date
- 3 Aug 2026
- Material Delta
- Broadcom added 8.0 U2f express-patch availability.
- Effect on Decision
- Changed the supported remediation choice for the 8.0 U2 branch.
- Evidence Status
- Vendor advisory revision.1
- Date
- 3–7 Aug 2026
- Material Delta
- QUIRSO reported compromised-system callbacks, rapid growth to 361 victim IPs in 47 countries, and reverse_ssh deployment.
- Effect on Decision
- Changed the issue from urgent preventive patching to patching plus retrospective compromise assessment for reachable systems.
- Evidence Status
- Primary researcher telemetry; not publicly confirmed by Broadcom or CISA.11
- Date
- 10 Aug 2026
- Material Delta
- QUIRSO published a generic YARA rule for standard NHAS reverse_ssh clients.
- Effect on Decision
- Added a practical host-artifact detection lead with a dual-use false-positive boundary.
- Evidence Status
- Primary detection content; generic to the tool, not unique to this campaign.12
- Date
- 16 Aug 2026 cutoff
- Material Delta
- No KEV entry, public campaign infrastructure, named victim, supported actor identity, or confirmed victim impact was retained.
- Effect on Decision
- Preserves high urgency while preventing unsupported attribution or loss claims.
| Date | Material Delta | Effect on Decision | Evidence Status |
|---|---|---|---|
| 29 Jul 2026 | Broadcom disclosed CVE-2026-59310, fixed supported branches, and listed no workaround. | Created an emergency remediation requirement for affected reachable vCenter systems. | Vendor-controlled vulnerability baseline.1, 2 |
| 3 Aug 2026 | Broadcom added 8.0 U2f express-patch availability. | Changed the supported remediation choice for the 8.0 U2 branch. | Vendor advisory revision.1 |
| 3–7 Aug 2026 | QUIRSO reported compromised-system callbacks, rapid growth to 361 victim IPs in 47 countries, and reverse_ssh deployment. | Changed the issue from urgent preventive patching to patching plus retrospective compromise assessment for reachable systems. | Primary researcher telemetry; not publicly confirmed by Broadcom or CISA.11 |
| 10 Aug 2026 | QUIRSO published a generic YARA rule for standard NHAS reverse_ssh clients. | Added a practical host-artifact detection lead with a dual-use false-positive boundary. | Primary detection content; generic to the tool, not unique to this campaign.12 |
| 16 Aug 2026 cutoff | No KEV entry, public campaign infrastructure, named victim, supported actor identity, or confirmed victim impact was retained. | Preserves high urgency while preventing unsupported attribution or loss claims. | Explicit negative-evidence boundary.5, 11 |
- Theme
- Pre-authentication code execution
- Why It Matters
- An attacker who can reach the affected service does not need a vCenter account or user click.
- Theme
- Central management-plane blast radius
- Why It Matters
- vCenter coordinates hosts, workloads, permissions, storage, networks, snapshots, and automation.
- Decision Consequence
- Scope connected infrastructure and recovery dependencies, not only the appliance.8
- Theme
- Observed exploitation
- Why It Matters
- QUIRSO reported 361 victim IP addresses across 47 countries and post-exploitation remote access.
- Decision Consequence
- Reachable systems require retrospective hunting in addition to version remediation.11
- Theme
- Outbound persistence channel
- Why It Matters
- reverse_ssh can initiate control traffic from the compromised system, crossing assumptions focused only on inbound firewall rules.
- Theme
- No vendor workaround
- Why It Matters
- Broadcom provides fixed releases but no workaround for the vulnerability.
- Theme
- Evidence can expire
- Why It Matters
- Rotated appliance, network, identity, and task/event records may disappear while teams schedule changes.
| Theme | Why It Matters | Decision Consequence |
|---|---|---|
| Pre-authentication code execution | An attacker who can reach the affected service does not need a vCenter account or user click. | Normal login MFA is not a substitute for patching or network restriction.1, 3 |
| Central management-plane blast radius | vCenter coordinates hosts, workloads, permissions, storage, networks, snapshots, and automation. | Scope connected infrastructure and recovery dependencies, not only the appliance.8 |
| Observed exploitation | QUIRSO reported 361 victim IP addresses across 47 countries and post-exploitation remote access. | Reachable systems require retrospective hunting in addition to version remediation.11 |
| Outbound persistence channel | reverse_ssh can initiate control traffic from the compromised system, crossing assumptions focused only on inbound firewall rules. | Review and constrain management-plane egress and investigate unexplained encrypted outbound sessions.11, 13 |
| No vendor workaround | Broadcom provides fixed releases but no workaround for the vulnerability. | Compensating controls reduce reachability but do not repair the vulnerable code.1, 2 |
| Evidence can expire | Rotated appliance, network, identity, and task/event records may disappear while teams schedule changes. | Preserve logs and task/event evidence before cleanup; document gaps when retention is insufficient.14, 15 |
- Date / Period
- 29 Jul 2026
- Event
- Broadcom publishes VMSA-2026-0006 after private researcher reporting and releases fixes.
- Why It Matters
- Starts the public exposure and remediation window.
- Date / Period
- 3 Aug 2026
- Event
- Broadcom revises the advisory to add 8.0 U2f express-patch availability.
- Why It Matters
- Adds a supported fix path for the U2 branch.
- Evidence Boundary
- Vendor change date, not campaign start evidence.1
- Date / Period
- 3 Aug 2026
- Event
- QUIRSO reports first compromised-system connections to attacker-controlled infrastructure.
- Why It Matters
- Earliest public campaign observation retained for this brief.
- Evidence Boundary
- Researcher telemetry; not a universal first-exploitation date.11
- Date / Period
- 4 Aug 2026
- Event
- QUIRSO reports 151 new victim IP addresses.
- Why It Matters
- Shows rapid early campaign growth.
- Evidence Boundary
- IP count does not equal organization count.11
- Date / Period
- 5 Aug 2026
- Event
- QUIRSO reports the observed victim-IP count reached 343.
- Why It Matters
- Supports broad exploitation urgency.
- Evidence Boundary
- Does not establish sector targeting or impact.11
- Date / Period
- 7 Aug 2026
- Event
- QUIRSO reports 361 victim IPs across 47 countries and post-access reverse_ssh use.
- Why It Matters
- Establishes the public scale and remote-access delta.
- Evidence Boundary
- Specific infrastructure and victim identities remained withheld.11
- Date / Period
- 10 Aug 2026
- Event
- QUIRSO dates its generic NHAS reverse_ssh YARA rule.
- Why It Matters
- Adds a defender detection artifact.
- Evidence Boundary
- The rule detects a dual-use tool, not CVE exploitation by itself.12
- Date / Period
- 13 Aug 2026
- Event
- BleepingComputer reports QUIRSO's findings and Broadcom's lack of response by publication time.
- Why It Matters
- Creates the wider public active-exploitation alert.
- Evidence Boundary
- Secondary publication does not convert withheld evidence into public IOCs.6
- Date / Period
- 16 Aug 2026
- Event
- IntelliOS research cutoff finds no KEV entry, named victim, supported actor attribution, or public campaign hash/infrastructure set.
- Why It Matters
- Defines the v1.1 evidence boundary.
| Date / Period | Event | Why It Matters | Evidence Boundary |
|---|---|---|---|
| 29 Jul 2026 | Broadcom publishes VMSA-2026-0006 after private researcher reporting and releases fixes. | Starts the public exposure and remediation window. | The advisory itself did not announce a victim incident.1, 2 |
| 3 Aug 2026 | Broadcom revises the advisory to add 8.0 U2f express-patch availability. | Adds a supported fix path for the U2 branch. | Vendor change date, not campaign start evidence.1 |
| 3 Aug 2026 | QUIRSO reports first compromised-system connections to attacker-controlled infrastructure. | Earliest public campaign observation retained for this brief. | Researcher telemetry; not a universal first-exploitation date.11 |
| 4 Aug 2026 | QUIRSO reports 151 new victim IP addresses. | Shows rapid early campaign growth. | IP count does not equal organization count.11 |
| 5 Aug 2026 | QUIRSO reports the observed victim-IP count reached 343. | Supports broad exploitation urgency. | Does not establish sector targeting or impact.11 |
| 7 Aug 2026 | QUIRSO reports 361 victim IPs across 47 countries and post-access reverse_ssh use. | Establishes the public scale and remote-access delta. | Specific infrastructure and victim identities remained withheld.11 |
| 10 Aug 2026 | QUIRSO dates its generic NHAS reverse_ssh YARA rule. | Adds a defender detection artifact. | The rule detects a dual-use tool, not CVE exploitation by itself.12 |
| 13 Aug 2026 | BleepingComputer reports QUIRSO's findings and Broadcom's lack of response by publication time. | Creates the wider public active-exploitation alert. | Secondary publication does not convert withheld evidence into public IOCs.6 |
| 16 Aug 2026 | IntelliOS research cutoff finds no KEV entry, named victim, supported actor attribution, or public campaign hash/infrastructure set. | Defines the v1.1 evidence boundary. | Status may change after the cutoff and should be monitored.5, 11, 12 |
- Phase
- 0–1 hour · Declare and own
- Action
- Assign infrastructure, security, business, and communications owners; classify each instance as unknown, fixed, vulnerable, or unsupported.
- Evidence / Output
- Instance register, owner, product packaging, critical workloads, and escalation channel.
- Phase
- 0–2 hours · Preserve
- Action
- Capture logs, support bundles, network flows, DNS, firewall, identity, task/event, backup, and configuration evidence before patching or rebooting rotates data.
- Evidence / Output
- Dated evidence manifest with retention gaps and chain-of-custody owner.
- Phase
- 0–2 hours · Map exposure
- Action
- Verify exact builds and actual paths from internet, VPN, corporate, partner, MSP, monitoring, backup, automation, and jump networks.
- Evidence / Output
- Observed routing and flow evidence, not architecture diagrams alone.
- Phase
- Immediate · Contain
- Action
- Remove direct public exposure, narrow access to approved administration paths, and constrain unexplained egress while preserving required operations.
- Evidence / Output
- Before/after firewall policy, allowed sources/destinations, exceptions, and approval.
- Phase
- Same day · Remediate
- Action
- Apply the current supported Broadcom fix for the exact branch or product-specific VCF/Telco procedure; do not rely on a compensating control as the repair.
- Evidence / Output
- Pre/post version and build, job output, health validation, and rollback evidence.
- Phase
- Same day–72 hours · Hunt
- Action
- Run the generic reverse_ssh YARA rule and correlate matches with files, services, processes, parentage, outbound connections, identities, roles, tasks, events, and infrastructure changes.
- Evidence / Output
- Positive and negative findings with host, time, source, analyst, and false-positive disposition.
- Phase
- Containment · Revoke trust
- Action
- If access is plausible, rotate vCenter/VCSA and reachable service credentials, SSH keys, API tokens, certificates, backup secrets, and privileged integration trust according to actual exposure.
- Evidence / Output
- Trust inventory, rotation proof, invalidated sessions, and downstream validation.
- Phase
- Recovery · Re-establish integrity
- Action
- Rebuild through a supported path when appliance integrity cannot be established; validate backups before relying on them and monitor the restored control plane.
- Evidence / Output
- Recovery source, integrity decision, restore validation, monitoring coverage, and residual risk sign-off.
- Exit Criterion
- A named authority accepts the evidence-backed integrity and residual-risk position.16
| Phase | Action | Evidence / Output | Exit Criterion |
|---|---|---|---|
| 0–1 hour · Declare and own | Assign infrastructure, security, business, and communications owners; classify each instance as unknown, fixed, vulnerable, or unsupported. | Instance register, owner, product packaging, critical workloads, and escalation channel. | Every instance has an accountable owner and response state.1, 8 |
| 0–2 hours · Preserve | Capture logs, support bundles, network flows, DNS, firewall, identity, task/event, backup, and configuration evidence before patching or rebooting rotates data. | Dated evidence manifest with retention gaps and chain-of-custody owner. | Available evidence for the full reachable vulnerable interval is preserved or gaps are recorded.14, 15 |
| 0–2 hours · Map exposure | Verify exact builds and actual paths from internet, VPN, corporate, partner, MSP, monitoring, backup, automation, and jump networks. | Observed routing and flow evidence, not architecture diagrams alone. | Each vulnerable interval has a defensible reachability classification.1, 3 |
| Immediate · Contain | Remove direct public exposure, narrow access to approved administration paths, and constrain unexplained egress while preserving required operations. | Before/after firewall policy, allowed sources/destinations, exceptions, and approval. | Only documented management paths can reach vCenter and abnormal egress is controlled.1, 11, 13 |
| Same day · Remediate | Apply the current supported Broadcom fix for the exact branch or product-specific VCF/Telco procedure; do not rely on a compensating control as the repair. | Pre/post version and build, job output, health validation, and rollback evidence. | Every supported instance is at a vendor-listed fixed build and service validation passed.1, 7 |
| Same day–72 hours · Hunt | Run the generic reverse_ssh YARA rule and correlate matches with files, services, processes, parentage, outbound connections, identities, roles, tasks, events, and infrastructure changes. | Positive and negative findings with host, time, source, analyst, and false-positive disposition. | The vulnerable interval and downstream management actions have been reviewed with documented confidence.11, 12, 14, 15 |
| Containment · Revoke trust | If access is plausible, rotate vCenter/VCSA and reachable service credentials, SSH keys, API tokens, certificates, backup secrets, and privileged integration trust according to actual exposure. | Trust inventory, rotation proof, invalidated sessions, and downstream validation. | Potentially exposed trust can no longer authenticate and dependent services are healthy.8, 16 |
| Recovery · Re-establish integrity | Rebuild through a supported path when appliance integrity cannot be established; validate backups before relying on them and monitor the restored control plane. | Recovery source, integrity decision, restore validation, monitoring coverage, and residual risk sign-off. | A named authority accepts the evidence-backed integrity and residual-risk position.16 |
- Term
- VMware vCenter Server
- Plain-Language Definition
- The centralized management system for ESXi hosts and virtual infrastructure.
- Why It Matters Here
- One appliance may coordinate many production systems and privileged operations.8
- Term
- VCSA
- Plain-Language Definition
- vCenter Server Appliance, the Photon OS-based appliance form of vCenter used in current releases.
- Why It Matters Here
- Host files, services, logs, processes, and outbound connections on this appliance are central to the hunt.14
- Term
- ESXi
- Plain-Language Definition
- VMware's bare-metal hypervisor that runs virtual machines and is commonly managed through vCenter.
- Why It Matters Here
- Suspicious vCenter actions may create downstream evidence on connected ESXi hosts and workloads.8
- Term
- vCenter Syslog server
- Plain-Language Definition
- The vCenter component Broadcom identifies as containing CVE-2026-59310.
- Why It Matters Here
- Do not confuse this component with every generic syslog receiver or with the separate VMware Directory Service flaw.1
- Term
- Directory / path traversal
- Plain-Language Definition
- A weakness that fails to keep a requested path within its intended directory boundary.
- Term
- Remote code execution (RCE)
- Plain-Language Definition
- The ability to make a remote system run attacker-chosen code.
- Term
- Unauthenticated / pre-authentication
- Plain-Language Definition
- The vulnerable path can be reached without first presenting valid application credentials.
- Term
- Network access
- Plain-Language Definition
- The attacker must be able to communicate with the affected vCenter service from some network position.
- Why It Matters Here
- Internet exposure enables initial access; internal restriction changes the attacker position required but does not remove the flaw.1
- Term
- NHAS reverse_ssh
- Plain-Language Definition
- An open-source SSH-based reverse-shell and remote-access framework whose client connects back to a server.
- Term
- Connect-back / callback
- Plain-Language Definition
- An outbound connection initiated by the controlled system toward operator infrastructure.
- Term
- YARA rule
- Plain-Language Definition
- A pattern-based rule used to identify files or memory content matching defined byte and string conditions.
- Why It Matters Here
- QUIRSO's rule detects standard reverse_ssh clients, not exploitation of CVE-2026-59310 by itself.12
- Term
- CISA KEV
- Plain-Language Definition
- The U.S. catalog of vulnerabilities for which CISA has reliable evidence of exploitation.
- Term
- Fixed build
- Plain-Language Definition
- A vendor-listed release containing the correction for the vulnerability.
- Why It Matters Here
- It proves the code is remediated now; it does not prove the system was never accessed before the update.1
- Term
- Enhanced Linked Mode / shared SSO domain
- Plain-Language Definition
- A vCenter arrangement that connects multiple instances through a common identity and management experience.
- Why It Matters Here
- Inventory and investigate every member separately; do not infer one node's patch or findings apply to all members.2
| Term | Plain-Language Definition | Why It Matters Here |
|---|---|---|
| VMware vCenter Server | The centralized management system for ESXi hosts and virtual infrastructure. | One appliance may coordinate many production systems and privileged operations.8 |
| VCSA | vCenter Server Appliance, the Photon OS-based appliance form of vCenter used in current releases. | Host files, services, logs, processes, and outbound connections on this appliance are central to the hunt.14 |
| ESXi | VMware's bare-metal hypervisor that runs virtual machines and is commonly managed through vCenter. | Suspicious vCenter actions may create downstream evidence on connected ESXi hosts and workloads.8 |
| vCenter Syslog server | The vCenter component Broadcom identifies as containing CVE-2026-59310. | Do not confuse this component with every generic syslog receiver or with the separate VMware Directory Service flaw.1 |
| Directory / path traversal | A weakness that fails to keep a requested path within its intended directory boundary. | Broadcom says this flaw can be used by a network-reachable attacker to execute arbitrary code.1, 9 |
| Remote code execution (RCE) | The ability to make a remote system run attacker-chosen code. | The public advisory establishes potential code execution but does not publish the request, payload, process lineage, or resulting privilege details.1, 3 |
| Unauthenticated / pre-authentication | The vulnerable path can be reached without first presenting valid application credentials. | Normal vCenter login controls and MFA cannot be assumed to protect this service path.1, 3 |
| Network access | The attacker must be able to communicate with the affected vCenter service from some network position. | Internet exposure enables initial access; internal restriction changes the attacker position required but does not remove the flaw.1 |
| NHAS reverse_ssh | An open-source SSH-based reverse-shell and remote-access framework whose client connects back to a server. | QUIRSO reports its post-exploitation deployment, but the tool is dual-use and requires contextual validation.11, 13 |
| Connect-back / callback | An outbound connection initiated by the controlled system toward operator infrastructure. | Outbound control can persist where inbound remote administration is blocked.11, 13 |
| YARA rule | A pattern-based rule used to identify files or memory content matching defined byte and string conditions. | QUIRSO's rule detects standard reverse_ssh clients, not exploitation of CVE-2026-59310 by itself.12 |
| CISA KEV | The U.S. catalog of vulnerabilities for which CISA has reliable evidence of exploitation. | The CVE was not listed at cutoff; that absence does not disprove QUIRSO's separately reported telemetry.5, 11 |
| Fixed build | A vendor-listed release containing the correction for the vulnerability. | It proves the code is remediated now; it does not prove the system was never accessed before the update.1 |
| Enhanced Linked Mode / shared SSO domain | A vCenter arrangement that connects multiple instances through a common identity and management experience. | Inventory and investigate every member separately; do not infer one node's patch or findings apply to all members.2 |
- Observed / Assessed Behavior
- Exploit a reachable vCenter Syslog service for arbitrary code execution
- ATT&CK Mapping
- T1190 · Exploit Public-Facing Application when externally reachable
- Confidence
- High for vulnerability capability; source-reported for campaign use
- Observed / Assessed Behavior
- Place or execute an NHAS reverse_ssh client
- ATT&CK Mapping
- T1105 · Ingress Tool Transfer; T1059 only if local evidence confirms an interpreter
- Confidence
- Source-reported tool deployment; exact transfer path unknown
- Observed / Assessed Behavior
- Initiate an outbound SSH-based remote-control channel
- ATT&CK Mapping
- T1219 · Remote Access Software; T1572 · Protocol Tunneling as an analytical possibility
- Confidence
- High for reverse_ssh capability; campaign destination details withheld
- Observed / Assessed Behavior
- Maintain continuing access through the deployed remote-access client
- ATT&CK Mapping
- Persistence tactic; exact persistence technique not public
- Confidence
- QUIRSO describes persistence but has not publicly released the mechanism
- Defender Use
- Review services, startup units, scheduled execution, SSH material, modified files, and unexplained restarts without assigning an unsupported technique.11
- Observed / Assessed Behavior
- Potential use of reachable management identities after appliance compromise
- ATT&CK Mapping
- T1078 · Valid Accounts only when owned evidence proves credential or account use
- Confidence
- Analytical hunt path, not a public campaign fact
- Observed / Assessed Behavior
- Potential manipulation of virtual infrastructure through vCenter control
- ATT&CK Mapping
- Impact, Discovery, Collection, or Defense Evasion techniques depend on the action actually observed
- Confidence
- Conditional consequence, not a universal campaign sequence
- Observed / Assessed Behavior
- Advanced-operator / APT characterization
- ATT&CK Mapping
- Not an ATT&CK technique
- Confidence
- Low; QUIRSO expressed a belief without public supporting attribution evidence
| Observed / Assessed Behavior | ATT&CK Mapping | Confidence | Defender Use |
|---|---|---|---|
| Exploit a reachable vCenter Syslog service for arbitrary code execution | T1190 · Exploit Public-Facing Application when externally reachable | High for vulnerability capability; source-reported for campaign use | Reconstruct reachability and review the vulnerable interval; do not require public exposure for internal exploitation.1, 11 |
| Place or execute an NHAS reverse_ssh client | T1105 · Ingress Tool Transfer; T1059 only if local evidence confirms an interpreter | Source-reported tool deployment; exact transfer path unknown | Review new files, downloads, package changes, services, execution parentage, and YARA matches.11, 12 |
| Initiate an outbound SSH-based remote-control channel | T1219 · Remote Access Software; T1572 · Protocol Tunneling as an analytical possibility | High for reverse_ssh capability; campaign destination details withheld | Baseline vCenter egress and investigate new encrypted sessions, long-lived connections, and uncommon destinations.11, 13 |
| Maintain continuing access through the deployed remote-access client | Persistence tactic; exact persistence technique not public | QUIRSO describes persistence but has not publicly released the mechanism | Review services, startup units, scheduled execution, SSH material, modified files, and unexplained restarts without assigning an unsupported technique.11 |
| Potential use of reachable management identities after appliance compromise | T1078 · Valid Accounts only when owned evidence proves credential or account use | Analytical hunt path, not a public campaign fact | Review new users, roles, service identities, keys, tokens, sessions, and privileged access from abnormal sources.8, 14 |
| Potential manipulation of virtual infrastructure through vCenter control | Impact, Discovery, Collection, or Defense Evasion techniques depend on the action actually observed | Conditional consequence, not a universal campaign sequence | Review tasks/events for snapshots, clones, exports, power actions, permissions, networks, storage, hosts, logging, and backup changes.8, 15 |
| Advanced-operator / APT characterization | Not an ATT&CK technique | Low; QUIRSO expressed a belief without public supporting attribution evidence | Keep behavior and attribution separate; do not label a nation-state or named group from tool choice.6, 11 |
- Question
- Can this provide initial access from the internet?
- Short Answer
- Yes, if the affected vCenter service is internet-reachable. No account or user action is required.
- Question
- What if vCenter is internal only?
- Short Answer
- The attacker first needs a position that can reach the management network, such as a compromised endpoint, VPN, partner, MSP, jump host, or other connected system.
- What To Do With the Answer
- Validate real routes and flow data; private addressing alone is not proof of isolation.1
- Question
- Does vCenter MFA stop this flaw?
- Short Answer
- Do not assume so. Broadcom describes a pre-authentication service flaw, so the normal interactive login path may never be invoked.
- Question
- Is exploitation theoretical?
- Short Answer
- No. QUIRSO reported compromised-system callbacks, 361 victim IPs in 47 countries, and reverse_ssh deployment.
- What To Do With the Answer
- Use the report to justify retrospective hunting while preserving the researcher-source boundary.11
- Question
- Is it in CISA KEV?
- Short Answer
- No, not as of the August 16 research cutoff.
- Question
- Do we know the victims or business impact?
- Short Answer
- No named organizations or verified data-theft, encryption, outage, or loss outcomes were retained. The public unit is 361 victim IP addresses.
- What To Do With the Answer
- Use owned evidence to establish organization scope and impact; do not convert IPs into company claims.11
- Question
- Are attacker IPs, domains, URLs, filenames, or hashes public?
- Short Answer
- No campaign-specific values in those categories were retained; QUIRSO says specific indicators were withheld during law-enforcement coordination.
- Question
- Does a reverse_ssh YARA match prove compromise?
- Short Answer
- No. The rule detects standard builds of a legitimate dual-use project and explicitly requires deployment context and telemetry.
- Question
- Is patching enough?
- Short Answer
- Patching removes the known vulnerable path but does not remove previously established access or prove no exploitation occurred.
- Question
- Who is behind it?
- Short Answer
- Unknown. QUIRSO suspects an advanced actor but did not publish evidence supporting a named attribution.
- Question
- What about older or integrated VMware environments?
- Short Answer
- The public response matrix covers supported branches and product-specific VCF/Telco paths; integrated or unsupported systems may need vendor guidance and accelerated migration.
| Question | Short Answer | What To Do With the Answer |
|---|---|---|
| Can this provide initial access from the internet? | Yes, if the affected vCenter service is internet-reachable. No account or user action is required. | Treat a publicly reachable vulnerable instance as an emergency exposure and preserve evidence before patching.1, 3 |
| What if vCenter is internal only? | The attacker first needs a position that can reach the management network, such as a compromised endpoint, VPN, partner, MSP, jump host, or other connected system. | Validate real routes and flow data; private addressing alone is not proof of isolation.1 |
| Does vCenter MFA stop this flaw? | Do not assume so. Broadcom describes a pre-authentication service flaw, so the normal interactive login path may never be invoked. | Keep MFA, but patch and restrict the vulnerable service.1, 3 |
| Is exploitation theoretical? | No. QUIRSO reported compromised-system callbacks, 361 victim IPs in 47 countries, and reverse_ssh deployment. | Use the report to justify retrospective hunting while preserving the researcher-source boundary.11 |
| Is it in CISA KEV? | No, not as of the August 16 research cutoff. | Do not wait for KEV; vendor severity, no workaround, and reported exploitation already justify urgent action.5, 11 |
| Do we know the victims or business impact? | No named organizations or verified data-theft, encryption, outage, or loss outcomes were retained. The public unit is 361 victim IP addresses. | Use owned evidence to establish organization scope and impact; do not convert IPs into company claims.11 |
| Are attacker IPs, domains, URLs, filenames, or hashes public? | No campaign-specific values in those categories were retained; QUIRSO says specific indicators were withheld during law-enforcement coordination. | Use the generic YARA rule and behavioral evidence rather than inventing a blocklist.11, 12 |
| Does a reverse_ssh YARA match prove compromise? | No. The rule detects standard builds of a legitimate dual-use project and explicitly requires deployment context and telemetry. | Correlate the match with owner, path, execution, process lineage, network activity, and authorization.12, 13 |
| Is patching enough? | Patching removes the known vulnerable path but does not remove previously established access or prove no exploitation occurred. | Patch and conduct a time-bounded compromise assessment for reachable vulnerable systems.1, 11 |
| Who is behind it? | Unknown. QUIRSO suspects an advanced actor but did not publish evidence supporting a named attribution. | Track an unattributed campaign; do not create or update a named threat-actor CARD.6, 11 |
| What about older or integrated VMware environments? | The public response matrix covers supported branches and product-specific VCF/Telco paths; integrated or unsupported systems may need vendor guidance and accelerated migration. | Do not improvise an unsupported standalone patch into an engineered stack.1, 2, 7 |
- Reference
- CVE-2026-59310
- Confirmed Status
- CVSS 3.1 9.8 Critical; AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; CWE-22.
- Operational Meaning
- Network-reachable, low-complexity, unauthenticated code-execution risk in the vCenter Syslog server.
- Reference
- CVE-2026-59309
- Confirmed Status
- Separate 9.8 vCenter VMware Directory Service authentication bypass in the same advisory.
- Operational Meaning
- The cumulative vCenter fixes address both critical issues.
- Reference
- vCenter / VCF / VSF 9.1.x
- Confirmed Status
- Current listed fixed release: 9.1.0.0300.
- Operational Meaning
- Record the full build and verify the installed release contains the cumulative correction.
- Boundary
- Do not use the CVE-2026-59309 first-fixed note as the CVE-2026-59310 fix statement.1
- Reference
- vCenter / VCF / VSF 9.0.x
- Confirmed Status
- Fixed release: 9.0.2.0100.
- Operational Meaning
- Update through the supported lifecycle path and validate health.
- Boundary
- Major version 9 alone is insufficient evidence.1
- Reference
- vCenter 8.0
- Confirmed Status
- Fixed releases listed: 8.0 U3k or 8.0 U2f.
- Operational Meaning
- Choose the supported branch-specific path and retain before/after build evidence.
- Boundary
- The August 3 revision added U2f express-patch availability.1
- Reference
- VMware Cloud Foundation 5.x
- Confirmed Status
- Use the asynchronous patch aligned with 8.0 U3k.
- Operational Meaning
- Coordinate through the VCF-supported process.
- Boundary
- Do not treat embedded vCenter as an ordinary standalone appliance change.1
- Reference
- Telco Cloud Platform / Infrastructure
- Confirmed Status
- Follow Broadcom KB449886 for listed 3.0–5.1.x branches.
- Operational Meaning
- Use product-specific remediation and compatibility guidance.
- Reference
- Workaround
- Confirmed Status
- None listed by Broadcom.
- Operational Meaning
- Patch is the durable repair; segmentation and egress controls are temporary risk reduction.
| Reference | Confirmed Status | Operational Meaning | Boundary |
|---|---|---|---|
| CVE-2026-59310 | CVSS 3.1 9.8 Critical; AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; CWE-22. | Network-reachable, low-complexity, unauthenticated code-execution risk in the vCenter Syslog server. | The exact request, endpoint, payload, privilege, and process chain are not public.1, 3, 9 |
| CVE-2026-59309 | Separate 9.8 vCenter VMware Directory Service authentication bypass in the same advisory. | The cumulative vCenter fixes address both critical issues. | No public source establishes a chain; do not merge its mechanics with CVE-2026-59310.1, 2 |
| vCenter / VCF / VSF 9.1.x | Current listed fixed release: 9.1.0.0300. | Record the full build and verify the installed release contains the cumulative correction. | Do not use the CVE-2026-59309 first-fixed note as the CVE-2026-59310 fix statement.1 |
| vCenter / VCF / VSF 9.0.x | Fixed release: 9.0.2.0100. | Update through the supported lifecycle path and validate health. | Major version 9 alone is insufficient evidence.1 |
| vCenter 8.0 | Fixed releases listed: 8.0 U3k or 8.0 U2f. | Choose the supported branch-specific path and retain before/after build evidence. | The August 3 revision added U2f express-patch availability.1 |
| VMware Cloud Foundation 5.x | Use the asynchronous patch aligned with 8.0 U3k. | Coordinate through the VCF-supported process. | Do not treat embedded vCenter as an ordinary standalone appliance change.1 |
| Telco Cloud Platform / Infrastructure | Follow Broadcom KB449886 for listed 3.0–5.1.x branches. | Use product-specific remediation and compatibility guidance. | A generic vCenter build statement is not enough for the Telco stack.1, 7 |
| Workaround | None listed by Broadcom. | Patch is the durable repair; segmentation and egress controls are temporary risk reduction. | A compensating control does not change the affected build.1, 2 |
No campaign-specific public blocklist is available. This register explicitly accounts for every common IOC category, publishes the primary generic detection content that is available, and separates it from local behavioral evidence.
- IOC / Observable Type
- Attacker IP addresses
- Public Value / Status
- Not public in retained sources; QUIRSO withheld specific infrastructure during law-enforcement coordination.
- Defender Use
- Prioritize unexpected outbound destinations from vCenter and preserve full flow/DNS context for later retro-hunting.
- Caveat
- Do not turn the 361 victim IP count into attacker infrastructure.11
- IOC / Observable Type
- Attacker domains / FQDNs
- Public Value / Status
- Not public in retained sources.
- Defender Use
- Review newly seen or rare vCenter-originated destinations and retain passive-DNS context where authorized.
- Caveat
- No unrelated reverse_ssh or VMware infrastructure should be imported.11
- IOC / Observable Type
- Attacker-controlled or malicious URLs
- Public Value / Status
- Not public in retained sources.
- Defender Use
- Review proxy, firewall, DNS, and appliance records for unusual outbound connection setup or downloads.
- IOC / Observable Type
- Malware filename / path
- Public Value / Status
- No campaign-specific filename or installation path is public.
- Defender Use
- Inventory files created or changed during the vulnerable interval and investigate unapproved Go binaries, services, and startup artifacts.
- IOC / Observable Type
- Malware file hash / SHA-256
- Public Value / Status
- No campaign-specific MD5, SHA-1, or SHA-256 value is public.
- Defender Use
- Hash locally discovered suspicious files and retain them for later matching as trusted sources publish updates.
- IOC / Observable Type
- YARA source file
- Public Value / Status
- 2026-08-10_reverse_ssh_generic.yar
- Defender Use
- Retrieve from QUIRSO's QTRDetectionContent repository, review internally, and scan appropriate appliance artifacts or collected images.
- Caveat
- Generic NHAS reverse_ssh detection, not a CVE exploit signature.12
- IOC / Observable Type
- YARA rule name
- Public Value / Status
- Tool_NHAS_Reverse_SSH_Client
- Defender Use
- Alert on matches and enrich with file path, owner, timestamps, execution, process lineage, network activity, and authorization.
- Caveat
- A match identifies reverse_ssh code; maliciousness depends on context.12
- IOC / Observable Type
- Binary byte pattern
- Public Value / Status
- Go build-info magic: FF 20 47 6F 20 62 75 69 6C 64 69 6E 66 3A
- Defender Use
- One required condition in QUIRSO's generic rule when combined with source-path and client-string matches.
- Caveat
- The byte pattern alone is common to Go binaries and is not malicious.12
- IOC / Observable Type
- Embedded source-path strings
- Public Value / Status
- github.com/NHAS/reverse_ssh/internal/client; /cmd/client; /internal/client/handlers; /pkg/mux; /internal/client/keys
- Defender Use
- Use as high-specificity strings within the full QUIRSO rule, not as independent proof.
- Caveat
- Standard builds may retain these paths; custom builds may differ.12
- IOC / Observable Type
- Client configuration strings
- Public Value / Status
- Connect-back address, server public-key fingerprint, missing-server-key, NTLM proxy credential, and file-based address/key configuration strings defined by the rule.
- Defender Use
- Correlate two or more rule strings with Go metadata and source paths as QUIRSO specifies.
- Caveat
- Do not alert on a paraphrased phrase or one isolated string.12
- IOC / Observable Type
- Network behavior
- Public Value / Status
- New or unexplained outbound SSH-like, tunnel, or long-lived encrypted sessions initiated by vCenter.
- Defender Use
- Compare destination, first seen, duration, bytes, process, owner, DNS, certificate/key context, and approved baseline.
- IOC / Observable Type
- Host / persistence behavior
- Public Value / Status
- Unexpected binaries, services, startup units, scheduled execution, SSH material, file modifications, or package activity on VCSA.
- Defender Use
- Correlate creation and execution time with the reachable vulnerable interval and network callbacks.
- IOC / Observable Type
- vCenter log evidence
- Public Value / Status
- /var/log/vmware/<Service Name>; vpxd.log; AIDE, RPM/DNF, untar, restore, proxy, and applicable Syslog records.
- Defender Use
- Review connections, internal tasks/events, file-integrity findings, package or extraction activity, restore activity, and service anomalies.
- Caveat
- Broadcom's log list is not exhaustive and no vendor CVE-specific log string is public.14
- IOC / Observable Type
- Management-plane actions
- Public Value / Status
- Unexpected tasks/events, users, roles, permissions, sessions, snapshots, clones, exports, power actions, host changes, storage/network changes, or backup activity.
- Defender Use
- Export and correlate tasks/events with account, source, object, start/completion time, result, and downstream host evidence.
- Caveat
- These are local compromise indicators, not globally malicious atomic IOCs.15
- IOC / Observable Type
- Evidence-gap observable
- Public Value / Status
- Missing or short-retention network, DNS, vCenter, task/event, identity, EDR, backup, or infrastructure logs during the vulnerable interval.
- Defender Use
- Record the missing source, time range, cause, and effect on confidence; compensate with remaining independent evidence.
| IOC / Observable Type | Public Value / Status | Defender Use | Caveat |
|---|---|---|---|
| Attacker IP addresses | Not public in retained sources; QUIRSO withheld specific infrastructure during law-enforcement coordination. | Prioritize unexpected outbound destinations from vCenter and preserve full flow/DNS context for later retro-hunting. | Do not turn the 361 victim IP count into attacker infrastructure.11 |
| Attacker domains / FQDNs | Not public in retained sources. | Review newly seen or rare vCenter-originated destinations and retain passive-DNS context where authorized. | No unrelated reverse_ssh or VMware infrastructure should be imported.11 |
| Attacker-controlled or malicious URLs | Not public in retained sources. | Review proxy, firewall, DNS, and appliance records for unusual outbound connection setup or downloads. | Vendor advisory and GitHub links are sources, not malicious URLs.1, 11, 12 |
| Malware filename / path | No campaign-specific filename or installation path is public. | Inventory files created or changed during the vulnerable interval and investigate unapproved Go binaries, services, and startup artifacts. | Do not assume the repository or YARA filename is the deployed client filename.11, 12 |
| Malware file hash / SHA-256 | No campaign-specific MD5, SHA-1, or SHA-256 value is public. | Hash locally discovered suspicious files and retain them for later matching as trusted sources publish updates. | A generic dual-use project has many legitimate or custom builds; do not manufacture a universal hash.11, 12, 13 |
| YARA source file | 2026-08-10_reverse_ssh_generic.yar | Retrieve from QUIRSO's QTRDetectionContent repository, review internally, and scan appropriate appliance artifacts or collected images. | Generic NHAS reverse_ssh detection, not a CVE exploit signature.12 |
| YARA rule name | Tool_NHAS_Reverse_SSH_Client | Alert on matches and enrich with file path, owner, timestamps, execution, process lineage, network activity, and authorization. | A match identifies reverse_ssh code; maliciousness depends on context.12 |
| Binary byte pattern | Go build-info magic: FF 20 47 6F 20 62 75 69 6C 64 69 6E 66 3A | One required condition in QUIRSO's generic rule when combined with source-path and client-string matches. | The byte pattern alone is common to Go binaries and is not malicious.12 |
| Embedded source-path strings | github.com/NHAS/reverse_ssh/internal/client; /cmd/client; /internal/client/handlers; /pkg/mux; /internal/client/keys | Use as high-specificity strings within the full QUIRSO rule, not as independent proof. | Standard builds may retain these paths; custom builds may differ.12 |
| Client configuration strings | Connect-back address, server public-key fingerprint, missing-server-key, NTLM proxy credential, and file-based address/key configuration strings defined by the rule. | Correlate two or more rule strings with Go metadata and source paths as QUIRSO specifies. | Do not alert on a paraphrased phrase or one isolated string.12 |
| Network behavior | New or unexplained outbound SSH-like, tunnel, or long-lived encrypted sessions initiated by vCenter. | Compare destination, first seen, duration, bytes, process, owner, DNS, certificate/key context, and approved baseline. | No universal campaign port or destination is public; legitimate administration can resemble this behavior.11, 13 |
| Host / persistence behavior | Unexpected binaries, services, startup units, scheduled execution, SSH material, file modifications, or package activity on VCSA. | Correlate creation and execution time with the reachable vulnerable interval and network callbacks. | QUIRSO has not publicly described the campaign's exact persistence mechanism.11, 14 |
| vCenter log evidence | /var/log/vmware/<Service Name>; vpxd.log; AIDE, RPM/DNF, untar, restore, proxy, and applicable Syslog records. | Review connections, internal tasks/events, file-integrity findings, package or extraction activity, restore activity, and service anomalies. | Broadcom's log list is not exhaustive and no vendor CVE-specific log string is public.14 |
| Management-plane actions | Unexpected tasks/events, users, roles, permissions, sessions, snapshots, clones, exports, power actions, host changes, storage/network changes, or backup activity. | Export and correlate tasks/events with account, source, object, start/completion time, result, and downstream host evidence. | These are local compromise indicators, not globally malicious atomic IOCs.15 |
| Evidence-gap observable | Missing or short-retention network, DNS, vCenter, task/event, identity, EDR, backup, or infrastructure logs during the vulnerable interval. | Record the missing source, time range, cause, and effect on confidence; compensate with remaining independent evidence. | No finding is not the same as a clean finding when required telemetry is absent.14, 15 |
- Actor / Label
- Campaign operator
- What Is Publicly Supported
- An unknown operator reportedly exploited vCenter and deployed reverse_ssh.
- What Is Not Supported
- Name, organization, sponsor, geography, motive, and victim-selection logic.
- Analyst Use
- Track as unattributed until corroborated evidence changes the record.11
- Actor / Label
- APT characterization
- What Is Publicly Supported
- QUIRSO reportedly believes an advanced actor is involved.
- What Is Not Supported
- Public evidence sufficient for a named APT or state attribution.
- Actor / Label
- QUIRSO
- What Is Publicly Supported
- The DFIR/threat-research source reporting the telemetry and publishing generic YARA detection content.
- What Is Not Supported
- It is not the actor and its withheld evidence is not available for independent public validation.
- Actor / Label
- NHAS reverse_ssh project
- What Is Publicly Supported
- An open-source dual-use SSH-based reverse-shell/remote-access framework reportedly abused after compromise.
- What Is Not Supported
- The project maintainers are not the campaign operator, and legitimate use is possible.
- Actor / Label
- Ransomware actor
- What Is Publicly Supported
- No reliable retained source connects this activity to ransomware.
- What Is Not Supported
- Ransomware family, affiliate, access broker, or extortion outcome.
| Actor / Label | What Is Publicly Supported | What Is Not Supported | Analyst Use |
|---|---|---|---|
| Campaign operator | An unknown operator reportedly exploited vCenter and deployed reverse_ssh. | Name, organization, sponsor, geography, motive, and victim-selection logic. | Track as unattributed until corroborated evidence changes the record.11 |
| APT characterization | QUIRSO reportedly believes an advanced actor is involved. | Public evidence sufficient for a named APT or state attribution. | Retain as low-confidence researcher assessment, not a headline fact.6, 11 |
| QUIRSO | The DFIR/threat-research source reporting the telemetry and publishing generic YARA detection content. | It is not the actor and its withheld evidence is not available for independent public validation. | Cite claims directly and preserve its stated limits.11, 12 |
| NHAS reverse_ssh project | An open-source dual-use SSH-based reverse-shell/remote-access framework reportedly abused after compromise. | The project maintainers are not the campaign operator, and legitimate use is possible. | Separate tool identity from attacker identity.12, 13 |
| Ransomware actor | No reliable retained source connects this activity to ransomware. | Ransomware family, affiliate, access broker, or extortion outcome. | Do not infer ransomware from virtualization targeting alone.5, 11 |
- Audience
- Board / executive
- Decision-Ready Message
- A reachable flaw could give an unauthenticated attacker code execution in the system that manages our virtual infrastructure; reported exploitation means patching alone is not closure.
- Audience
- Infrastructure
- Decision-Ready Message
- Identify every instance and exact build, use the supported branch-specific update, and prove actual network restriction rather than assuming private addressing is isolation.
- Audience
- SOC / DFIR
- Decision-Ready Message
- Use the generic reverse_ssh rule as one lead and correlate it with outbound traffic, files, services, tasks/events, identities, and management actions across the full vulnerable interval.
- Audience
- MSP / hosting
- Decision-Ready Message
- A shared vCenter or administration path can create concentration; isolate conclusions by customer and management plane.
- Proof To Request
- Tenant mapping, shared trust, customer-specific findings, containment, and notifications.8
- Audience
- Insurance / risk
- Decision-Ready Message
- The public record establishes material exposure and reported exploitation, not insured compromise or loss.
- Audience
- Legal / communications
- Decision-Ready Message
- Say what is vendor-confirmed, researcher-reported, locally observed, or still unknown; avoid actor, victim, and impact claims unsupported by owned evidence.
| Audience | Decision-Ready Message | Proof To Request |
|---|---|---|
| Board / executive | A reachable flaw could give an unauthenticated attacker code execution in the system that manages our virtual infrastructure; reported exploitation means patching alone is not closure. | Owner, affected systems, fixed builds, reachable interval, investigation result, recovery confidence, and residual risk.1, 8, 11 |
| Infrastructure | Identify every instance and exact build, use the supported branch-specific update, and prove actual network restriction rather than assuming private addressing is isolation. | Inventory, routing/flow evidence, change record, before/after builds, backup validation, and service health.1, 7, 16 |
| SOC / DFIR | Use the generic reverse_ssh rule as one lead and correlate it with outbound traffic, files, services, tasks/events, identities, and management actions across the full vulnerable interval. | Search scope, timestamps, data sources, positive/negative findings, false-positive disposition, and evidence gaps.12, 14, 15 |
| MSP / hosting | A shared vCenter or administration path can create concentration; isolate conclusions by customer and management plane. | Tenant mapping, shared trust, customer-specific findings, containment, and notifications.8 |
| Insurance / risk | The public record establishes material exposure and reported exploitation, not insured compromise or loss. | Reachability, unauthorized access, actions, affected data/systems, interruption, recovery cost, and uncertainty.5, 11 |
| Legal / communications | Say what is vendor-confirmed, researcher-reported, locally observed, or still unknown; avoid actor, victim, and impact claims unsupported by owned evidence. | Claim-to-source matrix and internally approved fact chronology.1, 6, 11 |
- Priority
- Now
- Owner
- Infrastructure
- Action
- Inventory every vCenter/VCF/VSF/Telco instance, exact build, owner, linked environment, and critical dependency.
- Priority
- Now
- Owner
- Network + security
- Action
- Map and reduce internet, VPN, partner, MSP, corporate, monitoring, backup, automation, and jump-host reachability.
- Completion Evidence
- Observed flow/routing proof and approved before/after policy.1
- Priority
- Before disruptive change
- Owner
- DFIR / SOC
- Action
- Preserve appliance, network, DNS, identity, tasks/events, integrations, and downstream infrastructure evidence.
- Priority
- Emergency
- Owner
- Infrastructure
- Action
- Apply the current vendor-listed fixed release or supported product-specific procedure.
- Priority
- Same day
- Owner
- SOC / DFIR
- Action
- Run contextual reverse_ssh detection and investigate outbound access, host persistence, identities, and management actions.
- Priority
- If access is plausible
- Owner
- Identity + platform
- Action
- Invalidate sessions and rotate credentials, keys, tokens, certificates, backup secrets, and integration trust that may have been exposed.
- Priority
- If integrity is uncertain
- Owner
- Incident commander
- Action
- Isolate and rebuild through a supported recovery path; validate backup provenance before restoration.
- Completion Evidence
- Integrity decision, recovery source, restored-state validation, and monitoring plan.16
- Priority
- Closure
- Owner
- Risk owner
- Action
- Separate fixed state, exposure conclusion, compromise conclusion, impact conclusion, and remaining uncertainty.
| Priority | Owner | Action | Completion Evidence |
|---|---|---|---|
| Now | Infrastructure | Inventory every vCenter/VCF/VSF/Telco instance, exact build, owner, linked environment, and critical dependency. | Signed instance register; unknown build is treated as affected until resolved.1, 7 |
| Now | Network + security | Map and reduce internet, VPN, partner, MSP, corporate, monitoring, backup, automation, and jump-host reachability. | Observed flow/routing proof and approved before/after policy.1 |
| Before disruptive change | DFIR / SOC | Preserve appliance, network, DNS, identity, tasks/events, integrations, and downstream infrastructure evidence. | Evidence manifest with timestamps, retention, custodian, and gaps.14, 15 |
| Emergency | Infrastructure | Apply the current vendor-listed fixed release or supported product-specific procedure. | Pre/post build, change result, service health, and supported-state confirmation.1, 7 |
| Same day | SOC / DFIR | Run contextual reverse_ssh detection and investigate outbound access, host persistence, identities, and management actions. | Search record and finding disposition covering the reachable vulnerable interval.11, 12, 14, 15 |
| If access is plausible | Identity + platform | Invalidate sessions and rotate credentials, keys, tokens, certificates, backup secrets, and integration trust that may have been exposed. | Trust inventory and rotation/validation record.8, 16 |
| If integrity is uncertain | Incident commander | Isolate and rebuild through a supported recovery path; validate backup provenance before restoration. | Integrity decision, recovery source, restored-state validation, and monitoring plan.16 |
| Closure | Risk owner | Separate fixed state, exposure conclusion, compromise conclusion, impact conclusion, and remaining uncertainty. | Approved closure memo with accountable residual-risk acceptance.1, 11 |
- Technology / Trust Path
- Internet-facing vCenter service
- Failure Mode
- Pre-authentication RCE reachable directly from an untrusted network.
- Plausible Consequence
- Initial foothold in the virtualization control plane.
- Technology / Trust Path
- Broad internal / VPN / partner reach
- Failure Mode
- An attacker with another foothold can reach the same vulnerable service.
- Plausible Consequence
- Lateral movement into high-value management infrastructure.
- Priority Control
- Dedicated management segmentation and verified source allowlists.1
- Technology / Trust Path
- Unrestricted VCSA egress
- Failure Mode
- A deployed client establishes an outbound remote-control path.
- Plausible Consequence
- Continuing access that bypasses inbound-only controls.
- Technology / Trust Path
- vCenter administrative trust
- Failure Mode
- Appliance compromise exposes powerful identities, permissions, integrations, and automation.
- Plausible Consequence
- Unauthorized actions across hosts, workloads, storage, networks, or recovery.
- Technology / Trust Path
- Linked or shared management
- Failure Mode
- Multiple instances or customers depend on common identity or administration paths.
- Plausible Consequence
- Concentration and cross-environment scoping complexity.
- Technology / Trust Path
- Backups controlled by the same plane
- Failure Mode
- Recovery material or credentials are reachable from the compromised management system.
- Plausible Consequence
- Uncertain recovery integrity and longer interruption.
- Priority Control
- Protected backup path, validation, separate trust, and supported restore procedure.16
- Technology / Trust Path
- Short or incomplete telemetry
- Failure Mode
- Logs rotate before the organization investigates the vulnerable interval.
- Plausible Consequence
- Inability to distinguish no compromise from no evidence.
| Technology / Trust Path | Failure Mode | Plausible Consequence | Priority Control |
|---|---|---|---|
| Internet-facing vCenter service | Pre-authentication RCE reachable directly from an untrusted network. | Initial foothold in the virtualization control plane. | Remove public reachability and patch immediately.1, 3 |
| Broad internal / VPN / partner reach | An attacker with another foothold can reach the same vulnerable service. | Lateral movement into high-value management infrastructure. | Dedicated management segmentation and verified source allowlists.1 |
| Unrestricted VCSA egress | A deployed client establishes an outbound remote-control path. | Continuing access that bypasses inbound-only controls. | Baseline, monitor, and restrict management-plane egress.11, 13 |
| vCenter administrative trust | Appliance compromise exposes powerful identities, permissions, integrations, and automation. | Unauthorized actions across hosts, workloads, storage, networks, or recovery. | Least privilege, separate service identities, rapid trust rotation, and task/event monitoring.8, 15 |
| Linked or shared management | Multiple instances or customers depend on common identity or administration paths. | Concentration and cross-environment scoping complexity. | Instance-by-instance inventory, segmentation, and customer-specific evidence.2, 8 |
| Backups controlled by the same plane | Recovery material or credentials are reachable from the compromised management system. | Uncertain recovery integrity and longer interruption. | Protected backup path, validation, separate trust, and supported restore procedure.16 |
| Short or incomplete telemetry | Logs rotate before the organization investigates the vulnerable interval. | Inability to distinguish no compromise from no evidence. | Immediate preservation, centralized logging, and explicit gap accounting.14, 15 |
Each tier is shown separately, including tiers with no configured or retained evidence. Selected counts refer to distinct retained sources, not repeated citations.
- Tier
- Tier 0
- Disposition
- 5 checked / 5 retained
- Retained Evidence
- NVD, CVE Program, CISA KEV, MITRE CWE, and MITRE ATT&CK.
- Tier
- Tier 1
- Disposition
- 4 advisory/product families checked / 7 retained records
- Retained Evidence
- Broadcom VMSA, FAQ, remediation KB, product overview, log, task/event, and backup guidance.
- Tier
- Tier 2
- Disposition
- 4 checked / 3 material primary research or tooling records retained
- Retained Evidence
- QUIRSO campaign publication, QUIRSO YARA content, and NHAS upstream project.
- Tier
- Tier 3
- Disposition
- 4 checked / 1 retained
- Retained Evidence
- BleepingComputer.
- Role / Limitation
- Corroborates and connects QUIRSO's records; not used as the sole source for vendor-controlled claims.6
- Tier
- Tier 4
- Disposition
- 3 public community/code signals checked / none used alone
- Retained Evidence
- No unverified social post or repost was elevated to a consequential claim.
- Tier
- Tier 5
- Disposition
- 0 configured
- Retained Evidence
- No user-defined custom source was available for this brief.
- Role / Limitation
- No inference from an unconfigured tier.1
- Tier
- Tier 6
- Disposition
- 0 configured or authorized
- Retained Evidence
- No private keyed integration contributed evidence.
- Role / Limitation
- The product remains public-source only.1
- Tier
- Tier 7
- Disposition
- 5 inner-discovery paths checked / 5 useful records retained across other evidence roles
- Retained Evidence
- Carved primary links from the advisory and QUIRSO reporting, including detection, upstream tool, logs, tasks/events, and backup records.
- Tier
- Tier 8
- Disposition
- 6 expansion checks / 3 material additions
- Retained Evidence
- Primary detection-content and operational evidence-location enrichment beyond the initial advisory/reporting baseline.
| Tier | Disposition | Retained Evidence | Role / Limitation |
|---|---|---|---|
| Tier 0 | 5 checked / 5 retained | NVD, CVE Program, CISA KEV, MITRE CWE, and MITRE ATT&CK. | Identifier, CNA record, KEV status, weakness class, and technique definitions; not campaign telemetry.3, 4, 5, 9, 10 |
| Tier 1 | 4 advisory/product families checked / 7 retained records | Broadcom VMSA, FAQ, remediation KB, product overview, log, task/event, and backup guidance. | Controls vulnerability, fixes, workaround, product role, and platform evidence locations.1, 2, 7, 8, 14, 15, 16 |
| Tier 2 | 4 checked / 3 material primary research or tooling records retained | QUIRSO campaign publication, QUIRSO YARA content, and NHAS upstream project. | Controls the researcher's observations and detection/tool descriptions; does not override vendor facts.11, 12, 13 |
| Tier 3 | 4 checked / 1 retained | BleepingComputer. | Corroborates and connects QUIRSO's records; not used as the sole source for vendor-controlled claims.6 |
| Tier 4 | 3 public community/code signals checked / none used alone | No unverified social post or repost was elevated to a consequential claim. | Discovery only unless independently verified; public GitHub primary content is cited within its own scope.12, 13 |
| Tier 5 | 0 configured | No user-defined custom source was available for this brief. | No inference from an unconfigured tier.1 |
| Tier 6 | 0 configured or authorized | No private keyed integration contributed evidence. | The product remains public-source only.1 |
| Tier 7 | 5 inner-discovery paths checked / 5 useful records retained across other evidence roles | Carved primary links from the advisory and QUIRSO reporting, including detection, upstream tool, logs, tasks/events, and backup records. | Discovery classification does not silently promote a source above its actual authority.12, 13, 14, 15, 16 |
| Tier 8 | 6 expansion checks / 3 material additions | Primary detection-content and operational evidence-location enrichment beyond the initial advisory/reporting baseline. | Expansion research adds decision utility but does not alter the vendor/CISA control hierarchy.12, 14, 15 |
- Apparent Tension
- Broadcom said no known exploitation at disclosure; QUIRSO later reported exploitation.
- Reconciliation
- The statements describe different dates and knowledge holders: July 29 vendor knowledge versus August 3–7 researcher telemetry.
- Apparent Tension
- Reported exploitation but no CISA KEV entry.
- Reconciliation
- KEV absence means CISA had not cataloged the CVE by the cutoff; it does not negate separate researcher observations.
- Apparent Tension
- Remote unauthenticated versus not necessarily internet-facing.
- Reconciliation
- No account is required, but a network path to the service is still required.
- Apparent Tension
- 361 victim IPs versus 361 victims or organizations.
- Reconciliation
- NAT, clustering, shared services, and multiple addresses prevent an organization-count inference.
- Decision Rule
- Use the reported unit exactly: victim IP addresses.11
- Apparent Tension
- reverse_ssh detected versus malicious compromise proven.
- Reconciliation
- The project is dual-use and the YARA rule is generic; context determines maliciousness.
- Apparent Tension
- Fixed build versus clean system.
- Reconciliation
- A patch closes the vulnerability prospectively but does not remove an existing remote-access client or reconstruct the past.
- Apparent Tension
- CVE-2026-59309 and CVE-2026-59310 share an advisory and score.
- Reconciliation
- They affect different components and have different descriptions; no chain is public.
- Decision Rule
- Patch both through the cumulative update but keep mechanics and evidence separate.1
| Apparent Tension | Reconciliation | Decision Rule |
|---|---|---|
| Broadcom said no known exploitation at disclosure; QUIRSO later reported exploitation. | The statements describe different dates and knowledge holders: July 29 vendor knowledge versus August 3–7 researcher telemetry. | Preserve both dated facts; do not call either one false.2, 11 |
| Reported exploitation but no CISA KEV entry. | KEV absence means CISA had not cataloged the CVE by the cutoff; it does not negate separate researcher observations. | Patch and hunt without waiting for KEV; label KEV status accurately.5, 11 |
| Remote unauthenticated versus not necessarily internet-facing. | No account is required, but a network path to the service is still required. | Classify initial-access versus post-foothold risk from actual reachability.1, 3 |
| 361 victim IPs versus 361 victims or organizations. | NAT, clustering, shared services, and multiple addresses prevent an organization-count inference. | Use the reported unit exactly: victim IP addresses.11 |
| reverse_ssh detected versus malicious compromise proven. | The project is dual-use and the YARA rule is generic; context determines maliciousness. | Correlate rule matches with deployment authorization, execution, traffic, and other compromise evidence.12, 13 |
| Fixed build versus clean system. | A patch closes the vulnerability prospectively but does not remove an existing remote-access client or reconstruct the past. | Track remediation and compromise assessment as separate closure requirements.1, 11 |
| CVE-2026-59309 and CVE-2026-59310 share an advisory and score. | They affect different components and have different descriptions; no chain is public. | Patch both through the cumulative update but keep mechanics and evidence separate.1 |
- Contributor
- Broadcom / VMware
- What They Do
- Publishes VMware security advisories, product guidance, fixed releases, and platform documentation.
- Why They Matter Here
- Controls vulnerability, severity, affected/fixed versions, no-workaround status, product role, logs, tasks/events, and backup guidance.
- Contributor
- Phil Brass and Matt South · Atredis Partners
- What They Do
- Security researchers credited with privately reporting the vulnerability.
- Why They Matter Here
- Explains why Broadcom opened the advisory and who discovered the defect.
- Contribution Limit
- No public exploit details or campaign attribution are assigned to them here.1
- Contributor
- QUIRSO Threat Research
- What They Do
- DFIR and threat research; reported exploitation telemetry and published detection content.
- Why They Matter Here
- Primary source for callbacks, victim-IP growth, geography, reverse_ssh deployment, and the generic YARA rule.
- Contributor
- NHAS reverse_ssh maintainers
- What They Do
- Maintain the upstream open-source SSH-based reverse-shell framework.
- Why They Matter Here
- Controls legitimate tool features and helps distinguish tool capability from campaign inference.
- Contribution Limit
- The project and maintainers are not attributed as malicious actors.13
- Contributor
- CISA
- What They Do
- Maintains the Known Exploited Vulnerabilities catalog.
- Why They Matter Here
- Controls whether the CVE is formally listed in KEV.
- Contribution Limit
- No listing at cutoff does not determine whether another source observed exploitation.5
- Contributor
- NVD / CVE Program / MITRE
- What They Do
- Normalize CVE, CNA, CWE, and ATT&CK records.
- Why They Matter Here
- Supports identifier, score/vector, weakness, and defensive technique language.
- Contributor
- BleepingComputer
- What They Do
- Independent security-news reporting that linked readers to QUIRSO's article and detection content.
- Why They Matter Here
- Corroborates the reporting chain and records Broadcom's lack of response by publication time.
- Contribution Limit
- Secondary reporting does not outrank primary vendor or researcher records.6
| Contributor | What They Do | Why They Matter Here | Contribution Limit |
|---|---|---|---|
| Broadcom / VMware | Publishes VMware security advisories, product guidance, fixed releases, and platform documentation. | Controls vulnerability, severity, affected/fixed versions, no-workaround status, product role, logs, tasks/events, and backup guidance. | Had not publicly confirmed the QUIRSO campaign by the cutoff.1, 2, 7, 8, 14, 15, 16 |
| Phil Brass and Matt South · Atredis Partners | Security researchers credited with privately reporting the vulnerability. | Explains why Broadcom opened the advisory and who discovered the defect. | No public exploit details or campaign attribution are assigned to them here.1 |
| QUIRSO Threat Research | DFIR and threat research; reported exploitation telemetry and published detection content. | Primary source for callbacks, victim-IP growth, geography, reverse_ssh deployment, and the generic YARA rule. | Withheld infrastructure and did not publish evidence supporting a named actor.11, 12 |
| NHAS reverse_ssh maintainers | Maintain the upstream open-source SSH-based reverse-shell framework. | Controls legitimate tool features and helps distinguish tool capability from campaign inference. | The project and maintainers are not attributed as malicious actors.13 |
| CISA | Maintains the Known Exploited Vulnerabilities catalog. | Controls whether the CVE is formally listed in KEV. | No listing at cutoff does not determine whether another source observed exploitation.5 |
| NVD / CVE Program / MITRE | Normalize CVE, CNA, CWE, and ATT&CK records. | Supports identifier, score/vector, weakness, and defensive technique language. | Does not supply the retained campaign infrastructure or victim-impact evidence.3, 4, 9, 10 |
| BleepingComputer | Independent security-news reporting that linked readers to QUIRSO's article and detection content. | Corroborates the reporting chain and records Broadcom's lack of response by publication time. | Secondary reporting does not outrank primary vendor or researcher records.6 |
- Public Example
- First compromised-system callbacks
- Date
- 3 Aug 2026
- What It Shows
- QUIRSO observed systems connecting to attacker-controlled infrastructure after disclosure.
- What It Does Not Show
- The public record does not identify the organizations or initial request artifacts.11
- Public Example
- Rapid victim-IP growth
- Date
- 4–7 Aug 2026
- What It Shows
- The count grew from 151 new victim IPs on August 4 to 361 total across 47 countries by August 7.
- What It Does Not Show
- It is not a count of unique companies, sectors, or confirmed material losses.11
- Public Example
- reverse_ssh deployment
- Date
- Observed campaign; public by 13 Aug 2026
- What It Shows
- The operator reportedly installed a dual-use outbound remote-access client after exploitation.
- Public Example
- Generic YARA publication
- Date
- 10 Aug 2026
- What It Shows
- QUIRSO released actionable detection content for standard NHAS reverse_ssh client binaries.
- What It Does Not Show
- A match alone does not prove CVE exploitation or malicious use.12
| Public Example | Date | What It Shows | What It Does Not Show |
|---|---|---|---|
| First compromised-system callbacks | 3 Aug 2026 | QUIRSO observed systems connecting to attacker-controlled infrastructure after disclosure. | The public record does not identify the organizations or initial request artifacts.11 |
| Rapid victim-IP growth | 4–7 Aug 2026 | The count grew from 151 new victim IPs on August 4 to 361 total across 47 countries by August 7. | It is not a count of unique companies, sectors, or confirmed material losses.11 |
| reverse_ssh deployment | Observed campaign; public by 13 Aug 2026 | The operator reportedly installed a dual-use outbound remote-access client after exploitation. | No public campaign hash, filename, infrastructure set, or persistence mechanism was retained.6, 11 |
| Generic YARA publication | 10 Aug 2026 | QUIRSO released actionable detection content for standard NHAS reverse_ssh client binaries. | A match alone does not prove CVE exploitation or malicious use.12 |
- Category
- Named victim organizations
- Public Record
- None retained.
- Confidence
- High that no reliable name was present in the retained source set at cutoff.
- Required Boundary
- Do not infer identity from geography, IP count, hosting provider, or screenshots.11
- Category
- Victim IP addresses
- Public Record
- 361 across 47 countries by August 7, per QUIRSO.
- Confidence
- Moderate-to-high within the researcher's telemetry scope.
- Required Boundary
- IP addresses are not equivalent to organizations or verified material-impact victims.11
- Category
- Geographic concentration
- Public Record
- More than half reportedly in Germany, the United States, Turkey, Iran, and France.
- Confidence
- Moderate within QUIRSO's observed set.
- Category
- Confirmed victim impact
- Public Record
- No named data theft, encryption, outage, destructive action, or financial loss retained.
- Confidence
- Unknown at organization level.
- Required Boundary
- Local evidence controls notification and loss conclusions.11
- Category
- Attacker infrastructure
- Public Record
- Withheld during law-enforcement coordination.
- Confidence
- High that public atomic values were intentionally unavailable in retained reporting.
- Required Boundary
- Do not invent or repurpose unrelated IPs/domains as campaign IOCs.11
| Category | Public Record | Confidence | Required Boundary |
|---|---|---|---|
| Named victim organizations | None retained. | High that no reliable name was present in the retained source set at cutoff. | Do not infer identity from geography, IP count, hosting provider, or screenshots.11 |
| Victim IP addresses | 361 across 47 countries by August 7, per QUIRSO. | Moderate-to-high within the researcher's telemetry scope. | IP addresses are not equivalent to organizations or verified material-impact victims.11 |
| Geographic concentration | More than half reportedly in Germany, the United States, Turkey, Iran, and France. | Moderate within QUIRSO's observed set. | Location does not establish targeting, sector, motive, or attribution.6, 11 |
| Confirmed victim impact | No named data theft, encryption, outage, destructive action, or financial loss retained. | Unknown at organization level. | Local evidence controls notification and loss conclusions.11 |
| Attacker infrastructure | Withheld during law-enforcement coordination. | High that public atomic values were intentionally unavailable in retained reporting. | Do not invent or repurpose unrelated IPs/domains as campaign IOCs.11 |
- Item
- CVE-2026-59310
- Current Status
- Published July 30; VMware CNA; Critical 9.8; CWE-22.
- Why It Matters
- Canonical vulnerability identity and severity baseline.
- Item
- CISA KEV
- Current Status
- Not listed as of 16 Aug 2026.
- Why It Matters
- No formal CISA KEV prioritization or federal due date at cutoff.
- Monitor For
- Addition date, required action, due date, and ransomware-use flag.5
- Item
- Exploitation status
- Current Status
- QUIRSO-reported active exploitation; not publicly confirmed by Broadcom or CISA at cutoff.
- Why It Matters
- Reachable vulnerable systems warrant compromise assessment now.
- Item
- Public proof of concept
- Current Status
- No issue-specific public exploit code retained.
- Why It Matters
- Absence does not reduce the vendor-defined severity or observed-activity urgency.
- Item
- Known ransomware use
- Current Status
- Not established.
- Why It Matters
- Do not add ransomware framing to the campaign without evidence.
- Item
- Named victims / impact
- Current Status
- None retained; 361 victim IPs are reported without organization identity or confirmed impact.
- Why It Matters
- Public scale supports urgency, not an organization-specific loss conclusion.
- Monitor For
- Primary victim disclosures or well-corroborated incident reports.11
- Item
- Vendor remediation
- Current Status
- Fixed builds available; no workaround.
- Why It Matters
- Supported update is mandatory; restrictions are temporary exposure reduction.
| Item | Current Status | Why It Matters | Monitor For |
|---|---|---|---|
| CVE-2026-59310 | Published July 30; VMware CNA; Critical 9.8; CWE-22. | Canonical vulnerability identity and severity baseline. | CNA/NVD changes to affected versions, scoring, references, or description.3, 4, 9 |
| CISA KEV | Not listed as of 16 Aug 2026. | No formal CISA KEV prioritization or federal due date at cutoff. | Addition date, required action, due date, and ransomware-use flag.5 |
| Exploitation status | QUIRSO-reported active exploitation; not publicly confirmed by Broadcom or CISA at cutoff. | Reachable vulnerable systems warrant compromise assessment now. | Vendor confirmation, additional primary telemetry, public exploit details, or authoritative detection guidance.1, 5, 11 |
| Public proof of concept | No issue-specific public exploit code retained. | Absence does not reduce the vendor-defined severity or observed-activity urgency. | Public exploit release or weaponization that changes defensive tempo.1, 11 |
| Known ransomware use | Not established. | Do not add ransomware framing to the campaign without evidence. | CISA or primary IR linkage to a named ransomware operation.5, 11 |
| Named victims / impact | None retained; 361 victim IPs are reported without organization identity or confirmed impact. | Public scale supports urgency, not an organization-specific loss conclusion. | Primary victim disclosures or well-corroborated incident reports.11 |
| Vendor remediation | Fixed builds available; no workaround. | Supported update is mandatory; restrictions are temporary exposure reduction. | Broadcom advisory or KB revisions and additional supported branch guidance.1, 2, 7 |
This lifecycle separates source-reported behavior from conditional investigation paths. It is not a claim that every victim experienced every phase.
- Lifecycle Phase
- Initial Access
- ATT&CK Technique
- T1190 · Exploit Public-Facing Application
- Evidence Level
- Vendor capability plus source-reported exploitation; applies as initial access only when externally reachable.
- Lifecycle Phase
- Lateral Movement / internal access
- ATT&CK Technique
- T1190 used from an existing reachable foothold
- Evidence Level
- Analytical placement based on network-access prerequisite.
- Detection / Validation
- Internal source paths, VPN/partner/MSP/jump reachability, and adjacent-host compromise evidence.1
- Lifecycle Phase
- Execution
- ATT&CK Technique
- Arbitrary code execution; T1059 only if an interpreter is observed
- Evidence Level
- Vendor confirms code-execution capability; exact campaign execution chain is not public.
- Lifecycle Phase
- Command and Control preparation
- ATT&CK Technique
- T1105 · Ingress Tool Transfer
- Evidence Level
- Reverse_ssh deployment reported; transfer method not public.
- Lifecycle Phase
- Command and Control
- ATT&CK Technique
- T1219 · Remote Access Software
- Evidence Level
- High for reported dual-use remote-access framework deployment.
- Lifecycle Phase
- Command and Control
- ATT&CK Technique
- T1572 · Protocol Tunneling
- Evidence Level
- Tool capability/analytical mapping; exact campaign tunnel use beyond remote access is not public.
- Detection / Validation
- Long-lived or multiplexed SSH-like traffic and internal service reach through the client.13
- Lifecycle Phase
- Persistence
- ATT&CK Technique
- Technique not publicly resolved
- Evidence Level
- QUIRSO describes persistence but withholds the exact mechanism.
- Detection / Validation
- Services, startup entries, scheduled execution, SSH keys, changed files, and recurring callbacks.11
- Lifecycle Phase
- Collection / Impact
- ATT&CK Technique
- No campaign technique assigned
- Evidence Level
- No named data theft, encryption, destructive action, or outage retained.
| Lifecycle Phase | ATT&CK Technique | Evidence Level | Detection / Validation |
|---|---|---|---|
| Initial Access | T1190 · Exploit Public-Facing Application | Vendor capability plus source-reported exploitation; applies as initial access only when externally reachable. | External exposure history, inbound source, service access, appliance changes, and post-access callbacks.1, 10, 11 |
| Lateral Movement / internal access | T1190 used from an existing reachable foothold | Analytical placement based on network-access prerequisite. | Internal source paths, VPN/partner/MSP/jump reachability, and adjacent-host compromise evidence.1 |
| Execution | Arbitrary code execution; T1059 only if an interpreter is observed | Vendor confirms code-execution capability; exact campaign execution chain is not public. | Process lineage, service execution, file changes, shell/interpreter telemetry, and timing correlation.1, 11 |
| Command and Control preparation | T1105 · Ingress Tool Transfer | Reverse_ssh deployment reported; transfer method not public. | Downloads, created files, package/extraction activity, and YARA-correlated artifacts.11, 12, 14 |
| Command and Control | T1219 · Remote Access Software | High for reported dual-use remote-access framework deployment. | Unexpected outbound encrypted sessions, first-seen destinations, process-to-socket mapping, and tool authorization.11, 13 |
| Command and Control | T1572 · Protocol Tunneling | Tool capability/analytical mapping; exact campaign tunnel use beyond remote access is not public. | Long-lived or multiplexed SSH-like traffic and internal service reach through the client.13 |
| Persistence | Technique not publicly resolved | QUIRSO describes persistence but withholds the exact mechanism. | Services, startup entries, scheduled execution, SSH keys, changed files, and recurring callbacks.11 |
| Collection / Impact | No campaign technique assigned | No named data theft, encryption, destructive action, or outage retained. | Tasks/events, snapshots, clones, exports, storage/network changes, backup activity, and downstream host evidence.11, 15 |
- Source / Class
- Broadcom VMSA / FAQ / KB
- Weight
- Controlling primary
- Used For
- Affected product, component, attack prerequisite, impact, CVSS, fixed versions, no workaround, and product-specific remediation.
- Source / Class
- NVD / CVE / CWE
- Weight
- Canonical
- Used For
- Identifier, CNA vector, description normalization, and weakness classification.
- Source / Class
- CISA KEV
- Weight
- Controlling government catalog
- Used For
- KEV listing, addition date, required action, due date, and ransomware-use flag when present.
- Does Not Establish
- Absence does not prove no exploitation occurred.5
- Source / Class
- QUIRSO publication
- Weight
- Primary researcher telemetry
- Used For
- Observed callback dates, victim-IP counts, geography, reverse_ssh deployment, and withheld-indicator boundary.
- Does Not Establish
- Does not independently establish a named actor, named victims, or universal impact.11
- Source / Class
- QUIRSO YARA repository
- Weight
- Primary detection content
- Used For
- Exact generic rule name, byte/string conditions, tool family, date, and dual-use warning.
- Does Not Establish
- Does not detect the CVE exploit request or prove malicious deployment alone.12
- Source / Class
- NHAS reverse_ssh repository
- Weight
- Authoritative upstream tool record
- Used For
- Legitimate tool identity and functionality.
- Does Not Establish
- Does not identify the campaign operator or confirm which build was deployed.13
- Source / Class
- Broadcom platform documentation
- Weight
- Primary operational reference
- Used For
- Log locations/content, task/event evidence, backup and restore considerations, and product role.
- Source / Class
- BleepingComputer
- Weight
- Corroborating secondary
- Used For
- Public reporting chronology, links to QUIRSO records, and Broadcom-response status at publication.
- Does Not Establish
- Cannot override vendor facts or make withheld indicators public.6
| Source / Class | Weight | Used For | Does Not Establish |
|---|---|---|---|
| Broadcom VMSA / FAQ / KB | Controlling primary | Affected product, component, attack prerequisite, impact, CVSS, fixed versions, no workaround, and product-specific remediation. | The retained vendor record does not confirm QUIRSO's campaign, victims, or actor.1, 2, 7 |
| NVD / CVE / CWE | Canonical | Identifier, CNA vector, description normalization, and weakness classification. | Does not provide campaign infrastructure, victim impact, or actor attribution.3, 4, 9 |
| CISA KEV | Controlling government catalog | KEV listing, addition date, required action, due date, and ransomware-use flag when present. | Absence does not prove no exploitation occurred.5 |
| QUIRSO publication | Primary researcher telemetry | Observed callback dates, victim-IP counts, geography, reverse_ssh deployment, and withheld-indicator boundary. | Does not independently establish a named actor, named victims, or universal impact.11 |
| QUIRSO YARA repository | Primary detection content | Exact generic rule name, byte/string conditions, tool family, date, and dual-use warning. | Does not detect the CVE exploit request or prove malicious deployment alone.12 |
| NHAS reverse_ssh repository | Authoritative upstream tool record | Legitimate tool identity and functionality. | Does not identify the campaign operator or confirm which build was deployed.13 |
| Broadcom platform documentation | Primary operational reference | Log locations/content, task/event evidence, backup and restore considerations, and product role. | Generic documentation is not issue-specific IOC or proof of compromise.8, 14, 15, 16 |
| BleepingComputer | Corroborating secondary | Public reporting chronology, links to QUIRSO records, and Broadcom-response status at publication. | Cannot override vendor facts or make withheld indicators public.6 |
PANDA CVE Watch Brief
VMware vCenter CVE-2026-59310 CVE Watch
Continuing watch for KEV, version, exploitation, IOC, victim, attribution, and remediation changes.
CARDS CVE
CVE-2026-59310 VMware vCenter RCE
Curated vulnerability, scope, exploitation, and connected-product card.
CARDS Campaign
VMware vCenter Reverse-SSH Exploitation
Unattributed campaign record preserving timing, behavior, scale, and evidence boundaries.
Rolling Intelligence Card
Exploitable Technology Risk
Cross-product view of exploited technologies and management-plane loss paths.
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
Monitoring posture
Watch Broadcom, CISA KEV, NVD/CVE, QUIRSO or corroborated telemetry, public IOCs, victim disclosures, and actor attribution for material changes.1, 3, 5, 6
Local proof
This public brief cannot determine whether any specific environment was vulnerable, reachable, exploited, persistent, or impacted. Owned evidence controls that conclusion.
- #
- 1
- Tier
- Tier 1
- Publisher
- Broadcom / VMware
- Published
- 29 Jul; updated 3 Aug 2026
- Why Used
- Controlling vulnerability, severity, vector, affected-product, fixed-version, and workaround source.
- Source
- VMSA-2026-0006.1
- #
- 2
- Tier
- Tier 1
- Publisher
- Broadcom / VMware
- Published
- Checked 16 Aug 2026
- Why Used
- Vendor clarification and disclosure-time exploitation boundary.
- #
- 3
- Tier
- Tier 0
- Publisher
- NIST NVD / VMware CNA
- Published
- 30 Jul; modified 14 Aug 2026
- Why Used
- Canonical description, CNA CVSS vector, CWE, and affected-version record.
- Source
- CVE-2026-59310
- #
- 4
- Tier
- Tier 0
- Publisher
- CVE Program
- Published
- Checked 16 Aug 2026
- Why Used
- Canonical identifier and CNA record.
- Source
- CVE-2026-59310 record
- #
- 5
- Tier
- Tier 0
- Publisher
- CISA
- Published
- Checked 16 Aug 2026
- Why Used
- Controls non-KEV status at the research cutoff.
- #
- 6
- Tier
- Tier 3
- Publisher
- BleepingComputer
- Published
- 13 Aug 2026
- Why Used
- Source-bounded QUIRSO campaign telemetry, scale, timing, geography, reverse_ssh behavior, and public-evidence limits.
- #
- 7
- Tier
- Tier 1
- Publisher
- Broadcom
- Published
- Checked 16 Aug 2026
- Why Used
- Product-specific Telco remediation guidance.
- #
- 8
- Tier
- Tier 1
- Publisher
- Broadcom / VMware
- Published
- Checked 16 Aug 2026
- Why Used
- Primary product-role and virtualization-management context.
- Source
- vCenter product overview
- #
- 9
- Tier
- Tier 0
- Publisher
- MITRE CWE
- Published
- Checked 16 Aug 2026
- Why Used
- Defines the vendor-assigned weakness class.
- Source
- CWE-22 — Path Traversal
- #
- 10
- Tier
- Tier 0
- Publisher
- MITRE ATT&CK
- Published
- Checked 16 Aug 2026
- Why Used
- Defensive lifecycle mapping for externally reachable exploitation.
- #
- 11
- Tier
- Tier 2
- Publisher
- QUIRSO Threat Research
- Published
- Checked 16 Aug 2026
- Why Used
- Primary researcher account for callback chronology, victim-IP scale, geography, reverse_ssh deployment, attribution limits, and withheld infrastructure.
- #
- 12
- Tier
- Tier 2
- Publisher
- QUIRSO Threat Research
- Published
- 10 Aug 2026
- Why Used
- Primary detection content with exact rule name, byte condition, source paths, client strings, filesize boundary, and dual-use limitation.
- #
- 13
- Tier
- Tier 2
- Publisher
- NHAS
- Published
- Checked 16 Aug 2026
- Why Used
- Primary upstream documentation for the dual-use reverse SSH framework and its outbound client/server operating model.
- #
- 14
- Tier
- Tier 1
- Publisher
- Broadcom
- Published
- Checked 16 Aug 2026
- Why Used
- Product-specific evidence map for VCSA service, vpxd, package, file-integrity, and related logs.
- #
- 15
- Tier
- Tier 1
- Publisher
- Broadcom
- Published
- Checked 16 Aug 2026
- Why Used
- Primary procedure for preserving and reviewing vCenter administrative tasks and events.
- #
- 16
- Tier
- Tier 1
- Publisher
- Broadcom
- Published
- Checked 16 Aug 2026
- Why Used
- Primary recovery context for supported vCenter backup and restore planning when appliance trust is in question.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 1 | Broadcom / VMware | 29 Jul; updated 3 Aug 2026 | Controlling vulnerability, severity, vector, affected-product, fixed-version, and workaround source. | VMSA-2026-0006.1 |
| 2 | Tier 1 | Broadcom / VMware | Checked 16 Aug 2026 | Vendor clarification and disclosure-time exploitation boundary. | VMSA-2026-0006 supplemental FAQ |
| 3 | Tier 0 | NIST NVD / VMware CNA | 30 Jul; modified 14 Aug 2026 | Canonical description, CNA CVSS vector, CWE, and affected-version record. | CVE-2026-59310 |
| 4 | Tier 0 | CVE Program | Checked 16 Aug 2026 | Canonical identifier and CNA record. | CVE-2026-59310 record |
| 5 | Tier 0 | CISA | Checked 16 Aug 2026 | Controls non-KEV status at the research cutoff. | Known Exploited Vulnerabilities Catalog |
| 6 | Tier 3 | BleepingComputer | 13 Aug 2026 | Source-bounded QUIRSO campaign telemetry, scale, timing, geography, reverse_ssh behavior, and public-evidence limits. | Critical VMware vCenter RCE flaw exploited for reverse SSH access |
| 7 | Tier 1 | Broadcom | Checked 16 Aug 2026 | Product-specific Telco remediation guidance. | Telco Cloud remediation matrix — KB449886 |
| 8 | Tier 1 | Broadcom / VMware | Checked 16 Aug 2026 | Primary product-role and virtualization-management context. | vCenter product overview |
| 9 | Tier 0 | MITRE CWE | Checked 16 Aug 2026 | Defines the vendor-assigned weakness class. | CWE-22 — Path Traversal |
| 10 | Tier 0 | MITRE ATT&CK | Checked 16 Aug 2026 | Defensive lifecycle mapping for externally reachable exploitation. | T1190 — Exploit Public-Facing Application |
| 11 | Tier 2 | QUIRSO Threat Research | Checked 16 Aug 2026 | Primary researcher account for callback chronology, victim-IP scale, geography, reverse_ssh deployment, attribution limits, and withheld infrastructure. | Active exploitation of CVE-2026-59310 — 361 victim IPs across 47 countries |
| 12 | Tier 2 | QUIRSO Threat Research | 10 Aug 2026 | Primary detection content with exact rule name, byte condition, source paths, client strings, filesize boundary, and dual-use limitation. | Generic NHAS reverse_ssh client YARA rule |
| 13 | Tier 2 | NHAS | Checked 16 Aug 2026 | Primary upstream documentation for the dual-use reverse SSH framework and its outbound client/server operating model. | reverse_ssh upstream project |
| 14 | Tier 1 | Broadcom | Checked 16 Aug 2026 | Product-specific evidence map for VCSA service, vpxd, package, file-integrity, and related logs. | Location and contents of vCenter Server log files |
| 15 | Tier 1 | Broadcom | Checked 16 Aug 2026 | Primary procedure for preserving and reviewing vCenter administrative tasks and events. | How to export vCenter tasks and events |
| 16 | Tier 1 | Broadcom | Checked 16 Aug 2026 | Primary recovery context for supported vCenter backup and restore planning when appliance trust is in question. | Overview of backup and restore options in vCenter Server |
- Version
- v1.1
- Date
- 16 Aug 2026
- Changes
- Full FortiBleed-exemplar QA revision. Rewrote the executive narrative in plain language; added the primary QUIRSO article, generic reverse_ssh YARA rule, upstream tool documentation, and Broadcom log/task/backup guidance; rebuilt IOC accounting, glossary, Q&A, source weighting, audience, response, ATT&CK, victim, contributor, and evidence-boundary cards; and added explicit unavailable IP, domain, URL, filename, and hash categories.
- Version
- v1.0
- Date
- 16 Aug 2026
- Changes
- Initial Flash Brief with vendor-controlled CVE facts, source-bounded QUIRSO campaign telemetry, fixed versions, access boundary, hunting, response, and CARDS reconciliation.
| Version | Date | Changes |
|---|---|---|
| v1.1 | 16 Aug 2026 | Full FortiBleed-exemplar QA revision. Rewrote the executive narrative in plain language; added the primary QUIRSO article, generic reverse_ssh YARA rule, upstream tool documentation, and Broadcom log/task/backup guidance; rebuilt IOC accounting, glossary, Q&A, source weighting, audience, response, ATT&CK, victim, contributor, and evidence-boundary cards; and added explicit unavailable IP, domain, URL, filename, and hash categories. |
| v1.0 | 16 Aug 2026 | Initial Flash Brief with vendor-controlled CVE facts, source-bounded QUIRSO campaign telemetry, fixed versions, access boundary, hunting, response, and CARDS reconciliation. |
