CVE-2026-59310 is a directory traversal flaw in the VMware vCenter Syslog service, rated CVSS 9.8, which lets an unauthenticated attacker with network access run arbitrary code. Broadcom released a fix on 29 July 2026.
The German incident response firm Quirso found an exploitation campaign during an engagement and published on 10 August. Compromised hosts first contacted attacker infrastructure on 3 August, five days after the fix. By 5 August around 95% of the victims Quirso observed had appeared. The firm counted 361 victim IP addresses across 47 countries, more than half in Germany, the United States, Turkey, Iran and France, with Babuk-derived ransomware deployed and reverse SSH access established.
The Window Was Two Days, Not Five
The interval that matters is not the five days between the patch and the first exploitation. It is the two days in which most of the damage was done.
An organisation that opened a change ticket on the Monday after disclosure had already missed it. Whatever the standard advice about prioritising critical patches is worth, the practical window here was shorter than most change-approval processes run.
vCenter Is Not An Application
A vCenter server administers the virtual machines underneath it. Code execution on it is not access to one system; it is authority over everything that console manages.
Management systems keep turning up at the start of these files — mobile device managers, print servers, self-service password tools. A hypervisor console belongs at the top of that list, and it is routinely reachable from the internet because administering it from elsewhere is convenient.
The Attribution Is A Working Pattern
Quirso assessed with moderate confidence that a Chinese-speaking actor ran the campaign, likely working in UTC+08:00. We are carrying that as the firm stated it and going no further.
Working hours and language artefacts are real evidence, and they are also the two easiest things to stage. Graded medium: the timeline and victim counts are well documented, the actor is not, and the counts describe one firm’s visibility rather than a census.
Compiled from Quirso’s published research, Broadcom’s advisory and public reporting, listed below. Victim counts are one firm’s visibility, not a census. The actor assessment is the researchers’ own, at moderate confidence. Corrections: corrections@forensicpost.com.