Hackers Actively Scanning to Exploit VMware VCenter Vulnerabilities
Brief
Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter fingerprinting activity. The activity includes requests to the /sdk/ endpoint using RetrieveServiceContent and exploration of the /websso single sign-on path.
The requests do not prove compromise but show that attackers are identifying exposed systems before launching more direct attacks.
The activity follows Broadcom’s VMSA-2026-0006 security advisory , released on July 29. The advisory covers five VMware flaws across vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and Telco Cloud products.
Three bugs received critical ratings. The most urgent issue for vCenter administrators is CVE-2026-59309, an authentication bypass in VMware Directory Service, vmdir. It has a CVSS score of 9. 8.
