Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-33824   (CVSS score: 9.8)  – Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040   (CVSS score: 9.1) Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310   (CVSS score: 9.8)   Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400  Apple macOS Improper Authentication Vulnerability CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310 , a critical path traversal bug in the Syslog Server, to run commands as root without a normal login. The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP addresses in 47 countries, with technology, research, education and telecommunications environments among the sectors exposed. The scale illustrates why vCenter management systems are such attractive targets. QUIRSO GmbH said in a report shared with Cyber Security News (CSN) that it investigated a compromise where the intrusion progressed from likely unauthenticated code execution to persistent access, account creation, ESXi control and ransomware.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-59310 - Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

·CISA KEV
Read →
Threat Actors & Campaigns
Emerging1 src

Critical VMware vCenter Flaw Exploited by Advanced APT

Enterprise virtualization infrastructure remains the primary target for advanced persistent threats seeking total network dominance. A devastating new attack campaign has proven that patching delays of even a few days can lead to catastrophic data center compromise. The VMware vCenter flaw CVE-2026-59310 is currently being actively exploited by a highly sophisticated, suspected advanced persistent threat ... Read more The post Critical VMware vCenter Flaw Exploited by Advanced APT appeared first on Cyber Updates 365 .

·Cyber Updates 365
Read →
Breaches & Ransomware
Emerging1 src

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access

An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks. Tracked as CVE-2026-59310 , the flaw is a maximum-severity directory-traversal vulnerability residing in the VMware vCenter Syslog server component. VMware vCenter Systems Exploited for Remote Access Broadcom released a security advisory warning that unauthenticated attackers with network access to an exposed vCenter instance can exploit the vulnerability to achieve remote code execution (RCE) with system privileges.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter Directory Traversal Flaw Used in Global Attacks

Broadcom VMware vCenter administrators are facing an intrusion campaign targeting CVE-2026-59310 , a critical directory-traversal vulnerability in the vCenter Syslog Server. Threat researchers at QUIRSO said they identified 361 unique victim IP addresses across 47 countries, with evidence suggesting a suspected advanced persistent threat is using the flaw to obtain code execution and establish remote access. The campaign shows attackers rapidly operationalizing weaknesses in exposed virtualization-management infrastructure. Broadcom issued advisory VMSA-2026-0006 on July 29, 2026. Critical VMware vCenter Directory Traversal Flaw QUIRSO observed affected systems begin connecting to attacker-controlled infrastructure on August 3 five calendar days later.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9. 8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310 . Both vulnerabilities carry CVSSv3. 1 base scores of 9. 8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical)

·Rapid7 Blog
Read →

You've reached the end of current stories for this search.