View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Exploit VMware vCenter CVE-2026-59310 for Persistent Access

๐Ÿšจ ACTIVE EXPLOITATION

  • Attackers Exploit VMware vCenter CVE-2026-59310 for Persistent Access CVE-2026-59310 Attackers are actively exploiting a critical VMware vCenter vulnerability.
    • Organizations running Broadcom VMware vCenter and related Cloud Foundation or vSphere Foundation products are affected.
    • CVE-2026-59310 is a CVSS 9.8 directory-traversal flaw in the vCenter Syslog Server that enables arbitrary code execution.
    • Attackers used path traversal to compromise vCenter appliances and deploy a malicious cron job running reverse_ssh for persistence.
    • QUIRSO identified 361 victim IP addresses across 47 countries, including Germany, the United States, Turkey, Iran, and France.
    • Broadcom fixed the flaw in vCenter 8.0 U3k, Foundation 9.0.2.0100, and Foundation 9.1.0.0300. ๐Ÿ“„ Source: medium.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ“‹ ADVISORIES

  • Intel and AMD Patch More Than 80 Vulnerabilities Combined Intel and AMD have patched more than 80 vulnerabilities across their products.

    • Intel and AMD customers are affected.
    • The flaws include high-severity vulnerabilities in Intel products.
    • Successful exploitation can enable privilege escalation or code execution. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • SP Page Builder 6.7.1 exposed Joomla sites to pre-auth RCE mySites.guru found a pre-authentication RCE in Joomla SP Page Builder.

    • Joomla sites using JoomShaper SP Page Builder are affected.
    • SP Page Builder 6.7.1 contains a PHP file-inclusion RCE and an arbitrary file-write flaw.
    • An anonymous request reaches the Dynamic Content "load more" endpoint using a CSRF token issued to unauthenticated visitors.
    • The endpoint derives filesystem paths from attacker-controlled addon data without traversal checks; both issues were fixed in version 6.8.0. ๐Ÿ“Ž Coverage: mysites.guru ยท ๐Ÿ‘ via mysites.guru (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-67282 โ€” CVSS 10.0 โ€” Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fa...
  • CVE-2026-66659 โ€” CVSS 9.3 โ€” Essekia Tablesome Table Critical Blind SQLi
  • CVE-2026-64952 โ€” CVSS 6.5 โ€” Velociraptor Hunt Deletion With Insufficient Permission CheckThe hunt_delete(...
  • CVE-2026-64955 โ€” CVSS 6.1 โ€” Velociraptor CSV Formula Injection in Export PipelineWhen Microsoft Excel imp...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check