Vulnerabilities

VMware vCenter RCE Vulnerability Exploited

August 14, 2026 04:08 · 10 min read
VMware vCenter RCE Vulnerability Exploited

VMware vCenter RCE Vulnerability Exploited for Reverse SSH Access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. According to digital forensics and incident response company QUIRSO, compromised systems started to connect to attacker-controlled infrastructure on August 3, just five days after Broadcom disclosed the flaw and released the emergency patch.

The campaign expanded quickly, with 151 new victim IP addresses being observed on August 4. By the next day, the count of victim IPs reached 343. However, QUIRSO notes that it identified a total of 361 victim IPs by August 7. These compromises have been identified at IP addresses across 47 countries, with more than half located in Germany, the U.S., Turkey, Iran, and France.

Vulnerability Details

Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that could be exploited by an unauthenticated attacker with network access to execute arbitrary code. The vendor provides no workarounds or mitigations and urges system administrators to apply the emergency update and consult the FAQ post for additional information.

The following vCenter releases address the security issue: vCenter 9.1: 9.1.0.0300, vCenter 9.0: 9.0.2.0100, and vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch. VMware vCenter is a centralized management software for controlling, monitoring, and configuring an organization’s VMware virtual infrastructure, including virtual machines, ESXi servers, configurations, and access permissions.

Attack Vector

After obtaining access to vulnerable vCenter systems, the attacker deployed the open-source reverse_ssh framework to establish persistence and gain remote access. The reverse SSH connection provides an outbound command-and-control (C2) channel and can also help bypass firewalls or other network security measures. QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries, although legitimate use of the tool also triggers the alert.

The researchers believe that an advanced persistent threat (APT) actor is behind the exploitation activity, although they provided no evidence to support this and are withholding specific indicators due to ongoing coordination with law enforcement authorities. QUIRSO plans a more detailed follow-up report that covers the attacker’s infrastructure, techniques, persistence, and post-exploitation activity.

Prevention and Mitigation

Once attackers have valid credentials, only 37% of their actions are blocked, according to The Blue Report 2026. This highlights the importance of robust security measures to prevent and detect such attacks. System administrators are urged to apply the emergency update and consult the FAQ post for additional information to prevent exploitation of the CVE-2026-59310 vulnerability.

BleepingComputer has contacted Broadcom for a statement on QUIRSO’s findings, but we have not received a response by publication time. As the situation develops, it is essential for organizations to remain vigilant and take proactive steps to protect their infrastructure from potential attacks.

Related Articles: Hackers target US firms in FastJson RCE zero-day attacks, CISA orders urgent action on actively exploited Langflow RCE flaw, Critical Langflow RCE flaw exploited to hack AI app servers, CISA sets urgent deadline to fix Cisco flaw exploited in attacks, CISA: Microsoft SharePoint flaw now exploited in ransomware attacks


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free