DEV Community

Cover image for Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Attackers Exploit Critical VMware vCenter Flaws to Gain Persistent Remote Access

Summary

German cybersecurity firm QUIRSO reports active exploitation of VMware vCenter and ESXi, critical flaws (CVE-2026-59310 and CVE-2026-59309).

Take Action:

If you run VMware vCenter, this is important. Make sure it is not reachable from the internet and can only be accessed from trusted internal networks. Then urgently apply the fixes from Broadcom advisory VMSA-2026-0006.1 (vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f), because the platform is being attacked and there is no workaround for the flaws. If your vCenter was exposed, check it for signs of compromise such as unexpected cron jobs, unknown SSH tools, or unusual outbound connections.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)