HispasecAugust 12, 2026🇪🇸Translated from Spanish

Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access

Attackers are actively exploiting the critical vulnerability CVE-2026-59310 in Broadcom VMware vCenter Server to gain persistent remote access on internet-exposed systems. The flaw affects the Syslog server component and allows unauthenticated remote code execution via a path traversal technique that lets adversaries manipulate file paths and execute arbitrary commands on the appliance.

The vulnerability carries a CVSS 9.8 severity rating, indicating near-complete compromise potential with minimal attacker effort. Exploitation activity began shortly after disclosure, with the first observed incidents recorded on 3 August 2026. Once initial access is obtained, threat actors establish persistence by installing malicious cron tasks and deploying the reverse_ssh utility, which creates stable outbound connections that often bypass inbound-focused defenses.

According to telemetry shared by researchers, the campaign has already compromised 361 unique victim IP addresses spread across 47 countries. The highest concentrations of affected systems were found in Germany, the United States, Turkey, Iran, and France. Many of these instances were directly reachable from the internet, dramatically increasing the speed and scale of successful attacks.

Broadcom has published official fixes in security advisory VMSA-2026-0006.1. The update resolves both CVE-2026-59310 and the related CVE-2026-59309. No alternative mitigations are available, so organizations must apply the patches without delay. Additional recommended actions include confirming that vCenter is not exposed to the internet, enforcing network segmentation and access-control lists, and auditing appliances for unauthorized cron entries, reverse_ssh binaries, and anomalous outbound connections.

Security researchers also noted a concurrent rise in scanning activity targeting the same attack surface, although a direct link to the ongoing exploitation of CVE-2026-59310 has not yet been confirmed. The short window between disclosure and active exploitation underscores the urgency of applying updates to virtualized infrastructure.

Related articles

HabrVulnerabilities & Exploits

Code Signing Myths: Why a Valid Digital Signature Does Not Equal File Safety

Digital signatures confirm only that a file was issued by a specific publisher at a given time and remained unchanged afterward. They do not verify current safety, the legitimacy of the current holder, or whether the private key was stolen months earlier. Attackers obtain legitimate certificates through build-system leaks, supply-chain compromises such as the 2019 ASUS ShadowHammer incident, or weak reseller validation. Expired certificates remain usable because verification can be performed at the timestamp recorded by an RFC 3161 TSA token rather than the current system clock. Signature hashes in Authenticode deliberately exclude the checksum field, certificate table, and attribute certificate table, allowing limited tampering that older WinVerifyTrust implementations did not fully block. Revocation checks are soft by default, and revocation dates can leave an exploitation window open. Organizations should enforce publisher thumbprint allow-lists in WDAC or AppLocker and store signing keys exclusively in HSMs.

HispasecVulnerabilities & Exploits

Attackers Exploit Critical Langflow and Ruby on Rails Flaws for Credential Theft and C2 Infrastructure

Active exploitation has been confirmed for CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails. Attackers first focus on reconnaissance and secret exfiltration before establishing command-and-control channels, with potential escalation to remote code execution. In Langflow the flaw allows arbitrary Python code execution as root due to insufficient input validation, enabling attackers to dump environment variables and locate cloud credentials. The Ruby on Rails issue, tracked as KindaRails2Shell, stems from an arbitrary file read triggered when Active Storage processes untrusted image uploads with libvips, exposing secret_key_base and other sensitive keys. Observed campaigns show traffic originating from Russia against Langflow instances and activity targeting canaries in Singapore, Israel, and the United Kingdom for Rails deployments. Defenders are advised to inventory public instances, apply the latest patches, rotate exposed secrets, and monitor for suspicious file reads and C2 communications.

Security NEXTVulnerabilities & Exploits

Critical Vulnerabilities in PaperCut NG and PaperCut MF Exploited in the Wild

PaperCut Software has disclosed two serious vulnerabilities in its printing management solutions PaperCut NG and PaperCut MF. The issues were detailed in an advisory published on August 27, 2026, followed by emergency patches. Exploitation has already been confirmed in customer environments. CVE-2026-81578 stems from improper access controls in the web management interface, allowing unauthenticated remote changes to system settings. CVE-2026-82078 involves insecure dynamic class loading in database connections, enabling arbitrary Java bytecode execution with server privileges when combined with the first flaw. CVSS scores are 9.4 (Critical) and 8.8 (High) respectively, and both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities Catalog.

HabrVulnerabilities & Exploits

Positive Technologies Develops Dynamic Crawler for Single-Page Applications in PT BlackBox Scanner

Positive Technologies engineers have detailed the development of a dynamic crawler for their PT BlackBox DAST scanner to handle modern single-page applications built with frameworks such as React and Vue. The crawler must discover attack surface elements that only appear after user interactions because static parsing of initial DOM fails on SPAs where navigation occurs without URL changes. Key challenges include identifying interactive elements whose handlers are attached via JavaScript, detecting state changes after clicks or inputs, and managing combinatorial explosion of states caused by independent UI toggles. The team models the application as a labeled transition system and defines state equivalence using sets of 64-bit fingerprints of interactive elements rather than raw HTML similarity or URL values. This equivalence relation satisfies reflexivity, determinism from external observations, cheap hash-based comparison, slower growth than action count, and preservation of enabled actions across equivalent states. The approach allows the crawler to visit representatives of equivalence classes instead of every reachable state, keeping scans finite and practical within action budgets of several thousand interactions.