Cybercriminals are now actively exploiting a newly patched vulnerability in Broadcom's VMware vCenter software, as revealed by recent research conducted by QUIRSO This article explores deployment malicious cron. . A vulnerability, identified as CVE-2026-59310 (CVSS score: 9.8), exists within the VMware vCenter server, allowing an attacker with network privileges to traverse directories and execute unauthorized code.

The attack chain involved path traversal, indicative of the flaw, followed by the deployment of a malicious cron job via reverse_ssh—a widely used tool for establishing persistence on hosts through SSH connections to threat actor-controlled infrastructure. SentinelOne disclosed details of a threat cluster dubbed PurpleHaze in April 2025, which targeted a South Asian government entity with a Windows backdoor called GoReShell.

The use of reverse_ssh, which allows the attacker to establish an outbound connection to their controlled endpoint, effectively bypasses security controls designed to prevent suspicious inbound requests. Our honeypots are logging increased fingerprinting activities such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow, coinciding with Broadcom's VMSA-2026-0006. Denis Szadkowski, COO and co-founder of QUIRSO GmbH, acknowledges that there is not enough evidence to correlate the exploitation and scanning efforts with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.