August 15, 2026
- VMware vCenter exploitation widened: Broadcom pushed VMSA-2026-0006.1, adding a critical auth-bypass (CVE-2026-59309, CVSS 9.8) and a VMXNET3 out-of-bounds write (CVE-2026-47876) alongside the directory-traversal RCE CVE-2026-59310 already under active APT exploitation for reverse-SSH persistence (Broadcom advisory, earlier coverage). · Vulnerabilities & Exploits