Affected Systems
Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.
Exploitation Status
Active exploitation confirmed since August 3, 2026 by suspected APT actor. QUIRSO observed successful compromises with path traversal activity and reverse_ssh persistence mechanisms deployed via malicious cron jobs. Exploitation began 5 days after public disclosure.
Business Impact
Critical remote code execution vulnerability (CVSS 9.8) allowing attackers with network access to execute arbitrary code via directory traversal. Successful exploitation leads to persistent access through reverse_ssh tunnels that bypass inbound security controls. VMware vCenter is a high-value target managing virtualized infrastructure; compromise enables lateral movement and long-term espionage. Activity attributed to likely APT actor, possibly China-nexus based on historical targeting patterns and reverse_ssh TTP overlap with PurpleHaze cluster.
Urgency
🔴 Immediate
Recommended Actions
- Apply Broadcom VMware vCenter patches released in late July 2026 (VMSA-2026-0006) immediately to all vCenter instances
- Hunt for indicators of compromise: unauthorized cron jobs, reverse_ssh binaries, and outbound SSH connections from vCenter appliances to unknown external IPs
- Review vCenter logs for path traversal patterns (directory traversal attempts) between July 28 and present, especially POST requests to /sdk/ and /websso endpoints
- Block or monitor outbound SSH connections from vCenter servers at network perimeter and investigate any reverse SSH tunnels to external infrastructure
- Isolate and forensically image any vCenter systems showing signs of compromise; coordinate with incident response teams for full scope assessment
