vCenter Overrun, AI-Written PLC Exploits, & Citrix Patches Again
Attackers went straight for the platforms that control critical parts of anyone’s environment: management planes, control systems, and edge appliances.
across 47 countries
to exploitation
exposed online
A suspected China-nexus APT weaponized a critical VMware vCenter flaw within five days of disclosure, hitting 361 victim IPs across 47 countries. Five U.S. agencies warned that threat actors are using AI-generated scripts to attack Siemens S7 PLCs across critical infrastructure. And Citrix is again urging admins to patch NetScaler, this time for an unauthenticated authentication bypass.
The common thread: management planes, control systems, and edge appliances are the highest-value targets in any environment, and the window between disclosure and exploitation is now measured in days.
VMware vCenter: 361 Victims in 47 Countries
CVE-2026-59310 / CVSS 9.8 / Directory traversal, no workaround · CVE-2026-59309 / Authentication bypass
Broadcom patched CVE-2026-59310 on July 29, a directory traversal flaw in the vCenter syslog server rated CVSS 9.8 with no workaround. Exploitation began five days later. Incident response firm QUIRSO tracked 361 victim IPs across 47 countries, 343 of them within roughly 48 hours, concentrated in technology, higher education, and telecommunications. Chinese-language artifacts, reused research from a Chinese security publication, and victimology excluding mainland China point to a Chinese-speaking APT.
Successful exploitation provides code execution as root on the vCenter appliance, with no privilege escalation required. The actor then used cron jobs impersonating legitimate VMware services to install a WebSocket backdoor, drop JSP web shells, add attacker SSH keys, and grant a service account passwordless sudo. Harvested vmdir credentials created rogue vSphere admin accounts. Some appliances were also hit with CVE-2026-59309, an authentication bypass patched the same day.
Babuk-derived ransomware appeared on ESXi hosts, but researchers suspect it was a smokescreen rather than the objective, since encrypting ESXi logs destroys the telemetry defenders need to reconstruct the intrusion.
Insights & Recommendations
- Patching Does Not Evict an IntruderTwo clocks are running: the patch clock and compromise clock. Audit cron entries, sudoers drops, authorized_keys, vSphere SSO group membership, and outbound connections on every appliance reachable before July 29.
- Never Expose the Management PlaneCompromise of vCenter extends far beyond a single host. Management interfaces belong behind mediated access, not anywhere a scanner can reach.
- Verify Post-Compromise ReachInternal Penetration Testing shows how far an attacker landing on a management appliance can travel, and Cybersecurity Incident Response is the right call the moment rogue accounts or unexplained cron jobs turn up.
AI-Generated Exploits Are Now Aimed at PLCs
Joint advisory / NSA, CISA, FBI, DOE, EPA · Siemens S7-200 through S7-1500 · Exposure, not a CVE
The NSA, CISA, FBI, DOE, and EPA issued a joint advisory on active targeting of Siemens S7 Series PLCs across critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Affected models span the S7-200 through S7-1500. The agencies were explicit that the targeting is broader than Siemens and that every PLC owner should act.
The tooling is what makes this different. Attackers are using AI to generate Python scripts built on the snap7 libraries, packaged to look like legitimate OT monitoring software, that provide full read and write access to PLC memory, configuration, and ladder logic over S7comm. Actors find exposed controllers through scanning services like Censys and ZoomEye and get in with default or weak credentials. Agencies assess this as reconnaissance ahead of future disruptive operations, not opportunistic crime.
Our advisory on the water utility campaign covered attackers taking over internet-facing Rockwell controllers without exploiting anything at all. This is the same root cause with a wider blast radius. The exposure is the vulnerability, and AI removes the requirement that an attacker understands industrial protocols first.
Insights & Recommendations
- Inventory Before Anything ElseIdentify every controller and firmware version, flag anything reachable from an untrusted network, and map every engineering workstation with programming access. Forgotten cellular modems and integrator-installed remote access are where these keep surfacing.
- Harden the Device ItselfEnable PLC password protection and write protection, restrict programming access through MAC and IP allowlisting, disable unused web servers and protocols, and enforce MFA on all remote OT access.
- Prove the Segmentation HoldsExternal Penetration Testing turns “we do not think anything is exposed” into a verified answer, Configuration Security Audits surface firewall and DMZ rules that have drifted since deployment, and a Tabletop Exercise tests whether operators can actually execute a manual failover.
Citrix NetScaler: Patch Before the Pattern Repeats
CVE-2026-19490 / Unauthenticated auth bypass · CVE-2026-19489 / Memory overflow, unauthenticated DoS
CVE-2026-19490 allows an unauthenticated remote attacker to bypass authentication when NetScaler is configured as an AAA virtual server or Gateway, covering SSL VPN, ICA Proxy, CVPN, and RDP Proxy deployments, depending on firmware version and SAML Action configuration. CVE-2026-19489 is a memory overflow enabling unauthenticated denial of service where SIP ALG is enabled on a large-scale NAT group. Neither is under active exploitation yet.
That “yet” is doing real work. Citrix issued a similar advisory in March for CVE-2026-3055 and CVE-2026-4368, and attackers began exploiting them within days. CISA has flagged 22 Citrix vulnerabilities as exploited in the wild over the past five years, six tied to ransomware. Shadowserver tracks more than 22,000 NetScaler ADC and nearly 1,800 Gateway instances exposed online.
Fixed versions: ADC and Gateway 14.1-73.32 or 13.1-63.21 and later, ADC FIPS 14.1-73.32 FIPS or later, and ADC FIPS and NDcPP 13.1-37.277 or later. SecurAccess ZTNA Hybrid deployments using customer-managed instances are also affected.
Insights & Recommendations
- Check Configuration, Then Patch RegardlessInspect for SAML action and auth or VPN vserver strings, and for lsn group SIP ALG strings. Configurations change, so appliances that do not currently meet the preconditions still need the update.
- Treat Edge Appliances as Priority AssetsVPN and application delivery devices sit at the perimeter and have a long ransomware track record. They deserve the shortest patch window in the environment, not the longest.
- Know What You Have ExposedContinuous Vulnerability Management catches the appliance nobody remembered was still in service, and External Penetration Testing validates what an unauthenticated attacker can actually reach.
Wrap
Three different technologies, one repeating failure mode. Attackers are not spending effort on novel exploits; they are going after infrastructure that already has privileged reach and is too often exposed, unpatched, or protected by credentials that were never changed. Prioritize management interfaces and edge appliances, verify what is actually reachable rather than assuming, and treat anything patched after public disclosure as potentially already occupied.
Not sure what you have exposed?nGuard validates it rather than assuming it, through penetration testing, configuration audits, and continuous vulnerability management.
Talk to nGuard
