CVE-2026-59310: Critical Directory Traversal in Broadcom VMware vCenter

Last Updated: Friday, August 14, 2026 1:25 AM

What’s Happening

On Wednesday, July 29th, 2026 Broadcom released a security advisory for a directory traversal vulnerability in VMware’s vCenter. On the same day, the security researchers published a detailed walkthrough for the vulnerability. August 3rd, QUIRSO GmbH observed active exploitation of the vulnerability. Broadcom has released patches for the vulnerability. There is no other workaround.

Broadcom’s Security Advisory:

QUIRSO’s report:

https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff

QUIRSO’s YARA rule:

https://github.com/QUIRSO/QTRDetectionContent/blob/main/2026-08-10_reverse_ssh_generic.yar

Atredis’ walkthrough:

https://github.com/atredispartners/advisories/blob/master/2026/ATREDIS-2026-0008.md

Actions

Update to the latest version of vCenter, apply the security patches as per Broadcom’s recommendations.

QUIRSO has published a YARA rule for detecting reverse_ssh which can be used to threat hunt on your environment (with some caveats).

Notes

The POC also included CVE-2026-59309 (VMware vCenter Auth Bypass)

https://www.cve.org/CVERecord?id=CVE-2026-59310

https://www.cve.org/CVERecord?id=CVE-2026-59309

1 Like