HispasecAugust 12, 2026🇪🇸Translated from Spanish

Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access

Attackers are actively exploiting the critical vulnerability CVE-2026-59310 in Broadcom VMware vCenter Server to gain persistent remote access on internet-exposed systems. The flaw affects the Syslog server component and allows unauthenticated remote code execution via a path traversal technique that lets adversaries manipulate file paths and execute arbitrary commands on the appliance.

The vulnerability carries a CVSS 9.8 severity rating, indicating near-complete compromise potential with minimal attacker effort. Exploitation activity began shortly after disclosure, with the first observed incidents recorded on 3 August 2026. Once initial access is obtained, threat actors establish persistence by installing malicious cron tasks and deploying the reverse_ssh utility, which creates stable outbound connections that often bypass inbound-focused defenses.

According to telemetry shared by researchers, the campaign has already compromised 361 unique victim IP addresses spread across 47 countries. The highest concentrations of affected systems were found in Germany, the United States, Turkey, Iran, and France. Many of these instances were directly reachable from the internet, dramatically increasing the speed and scale of successful attacks.

Broadcom has published official fixes in security advisory VMSA-2026-0006.1. The update resolves both CVE-2026-59310 and the related CVE-2026-59309. No alternative mitigations are available, so organizations must apply the patches without delay. Additional recommended actions include confirming that vCenter is not exposed to the internet, enforcing network segmentation and access-control lists, and auditing appliances for unauthorized cron entries, reverse_ssh binaries, and anomalous outbound connections.

Security researchers also noted a concurrent rise in scanning activity targeting the same attack surface, although a direct link to the ongoing exploitation of CVE-2026-59310 has not yet been confirmed. The short window between disclosure and active exploitation underscores the urgency of applying updates to virtualized infrastructure.

Related articles

BoletimSecVulnerabilities & Exploits

SAP Releases August Security Update Patching 28 Vulnerabilities Including Critical CVSS 10 Flaw

SAP has issued a broad security update to address multiple critical vulnerabilities that could enable code injection, memory corruption, and privilege escalation across enterprise systems. The August package includes 28 new security notes along with a GitHub advisory and two prior fix updates. The highest-severity issue, CVE-2026-58231, carries a maximum CVSS score of 10 and affects the Data Hub Adapter in SAP Commerce Cloud versions 2211 and 2211-JDK21, allowing remote exploitation without user interaction due to improper authorization. Another critical flaw, CVE-2026-44772 rated 9.9, impacts SAP Manufacturing Integration and Intelligence 15.4 and 15.5, permitting malicious code injection into industrial process monitoring systems. Additional vulnerabilities rated 9.1 and lower cover directory traversal, SQL injection, XSS, XXE, hardcoded credentials, and OS command injection across various corporate components. Administrators are advised to identify affected systems and prioritize installation of the critical patches first.

BoletimSecVulnerabilities & Exploits

Zoom Patches Zoomsday Vulnerability Enabling Remote Code Execution in Meetings

Zoom has addressed four vulnerabilities that could allow attackers to compromise meeting participants, including flaws leading to remote code execution without any victim interaction. The most severe issue, CVE-2026-53413, rated 8.3 and nicknamed Zoomsday, resides in the annotation feature used for drawing, highlighting, or adding text during screen sharing. This component processes network data using fixed 128-byte buffers without proper size validation, enabling memory corruption that alters program execution flow. Researchers demonstrated the attack on macOS by silently launching Safari on the victim's machine. The flaws affect Zoom Workplace, Zoom Rooms, Meeting SDK, and VDI clients. Users must update to patched versions such as Workplace 7.1.5 or 7.0.6, and Zoom Rooms or Meeting SDK 7.1.5 to mitigate annotation-related risks. No active exploitation has been observed publicly, yet centralized enterprise deployments require priority updates since attacks can occur during live meetings.

HabrVulnerabilities & Exploits

Agent, Scan or Beyond: Modern Methods for Comprehensive Infrastructure Vulnerability Scanning

The eighth installment in the Vulnerability Management for Beginners series explains why traditional scanning approaches no longer cover today's dynamic environments. It details three classic methods—Host Discovery, Pentest, and Audit—alongside agent-based scanning, cloud snapshot techniques, passive traffic analysis, container and SCA tools, and integrations with existing IT systems. The guide stresses that agents from Tenable and Qualys complement but do not replace network scanning, while Orca Security and Wiz pioneered disk snapshot analysis for short-lived cloud instances. It also covers container image scanning with Trivy and Grype before deployment, passive monitoring for OT environments, and the importance of combining multiple data sources to eliminate blind spots. Practical recommendations include scanning frequency by asset type and six post-scan steps for effective remediation.

Security NEXTVulnerabilities & Exploits

CVE-2026-20349: Cisco ASA and FTD Firewalls Face Remote DoS in SSL VPN, Already Exploited

Cisco has disclosed a high-severity denial-of-service vulnerability affecting its Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense products. The flaw, tracked as CVE-2026-20349, resides in the SSL VPN component and allows unauthenticated remote attackers to trigger device reboots by sending specially crafted HTTP requests. The issue also impacts FTD deployments using Zero Trust Network Access. With a CVSS v3.1 base score of 8.6, the vulnerability has already been observed in active exploitation campaigns since August 2026. Cisco released hotfixes for both affected platforms and strongly urges immediate updates, while confirming that Secure Firewall Management Center remains unaffected.