Last Updated: Friday, August 14, 2026 1:25 AM
What’s Happening
On Wednesday, July 29th, 2026 Broadcom released a security advisory for a directory traversal vulnerability in VMware’s vCenter. On the same day, the security researchers published a detailed walkthrough for the vulnerability. August 3rd, QUIRSO GmbH observed active exploitation of the vulnerability. Broadcom has released patches for the vulnerability. There is no other workaround.
Broadcom’s Security Advisory:
QUIRSO’s report:
QUIRSO’s YARA rule:
https://github.com/QUIRSO/QTRDetectionContent/blob/main/2026-08-10_reverse_ssh_generic.yar
Atredis’ walkthrough:
https://github.com/atredispartners/advisories/blob/master/2026/ATREDIS-2026-0008.md
Actions
Update to the latest version of vCenter, apply the security patches as per Broadcom’s recommendations.
QUIRSO has published a YARA rule for detecting reverse_ssh which can be used to threat hunt on your environment (with some caveats).
Notes
The POC also included CVE-2026-59309 (VMware vCenter Auth Bypass)