Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Adobe ColdFusion flaws let attackers run arbitrary code
August 12, 2026
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
Home/CyberSecurity News/Critical VMware vCenter flaw exploited for remote access
CyberSecurity News

Critical VMware vCenter flaw exploited for remote access

Key Takeaways A critical directory traversal vulnerability, CVE-2026-59310, in VMware vCenter’s Syslog server component is under active exploitation. Advanced Persistent Threat (APT) actors are...

Jennifer sherman
Jennifer sherman
August 12, 2026 3 Min Read
3 0

Key Takeaways

  • A critical directory traversal vulnerability, CVE-2026-59310, in VMware vCenter’s Syslog server component is under active exploitation.
  • Advanced Persistent Threat (APT) actors are leveraging this flaw to gain initial access and deploy reverse SSH backdoors.
  • The vulnerability carries a CVSS score of 9.8, indicating maximum severity and remote code execution potential.
  • Patches are available for vCenter versions 9.1, 9.0, and 8.0, and immediate application is mandatory as no workarounds exist.

Widespread Exploitation of Critical VMware vCenter Flaw for Remote Access

Cybersecurity analysts have uncovered an ongoing campaign targeting internet-exposed VMware vCenter instances. Threat actors are actively exploiting CVE-2026-59310, a severe vulnerability within the vCenter Syslog server, to establish initial footholds and deploy persistent reverse SSH tools for long-term access to compromised networks.

Table Of Content

  • Key Takeaways
  • Widespread Exploitation of Critical VMware vCenter Flaw for Remote Access
  • The Vulnerability: CVE-2026-59310
  • Rapid Exploitation Post-Disclosure
  • Global Impact and Attacker Tooling
  • What You Should Do

The Vulnerability: CVE-2026-59310

Designated CVE-2026-59310, this critical flaw is a directory traversal vulnerability impacting the VMware vCenter Syslog server component. With a CVSS score of 9.8, it poses an extreme risk, allowing unauthenticated attackers with network access to an exposed vCenter instance to achieve remote code execution (RCE) with system-level privileges. Broadcom confirmed the absence of temporary workarounds or mitigations, making immediate patching essential to protect virtualized infrastructure.

Organizations running vulnerable vCenter versions are urged to apply the following remediated releases:

Deployed Branch Remediated Release Vendor Advisory
VMware vCenter 9.1 Version 9.1.0.0300 VMSA-2026-0006.1
VMware vCenter 9.0 Version 9.0.2.0100 VMSA-2026-0006.1
VMware vCenter 8.0 Version 8.0 U3k or 8.0 U2f VMSA-2026-0006.1

Rapid Exploitation Post-Disclosure

The window between public disclosure and active exploitation of CVE-2026-59310 was remarkably short. Broadcom issued its security advisory, VMSA-2026-0006, on July 29, 2026. Just five days later, on August 3, QUIRSO first detected compromised systems communicating with attacker-controlled command-and-control (C2) infrastructure.

Exploitation efforts escalated quickly. On August 4, an additional 151 victim IP addresses were observed connecting to C2 infrastructure. By August 5, approximately 95 percent of the 361 identified victim systems had already been compromised. This rapid timeline underscores the aggressive nature of threat actors in scanning for and exploiting newly disclosed vulnerabilities.

Global Impact and Attacker Tooling

Telemetry data indicates that compromised systems are geographically dispersed across 47 countries. More than half of the identified victim IP addresses are concentrated in five nations:

  • Germany: 55 unique IPs
  • United States: 41 unique IPs
  • Turkey: 38 unique IPs
  • Iran: 26 unique IPs
  • France: 25 unique IPs

Following successful exploitation of the vCenter Syslog service, attackers are deploying reverse_ssh, an open-source SSH-based reverse-shell tool written in Go. This tool grants attackers robust post-exploitation capabilities, including:

  • Automated Connect-Backs: Enables periodic outbound SSH connections to maintain remote channels.
  • Port Forwarding: Facilitates local and remote dynamic port forwarding for lateral movement across internal subnets.
  • File Transfer: Built-in SCP/SFTP capabilities simplify the staging and exfiltration of sensitive virtual machine files.
  • Firewall Evasion: Establishes outbound control connections on standard ports, often bypassing inbound perimeter firewall rules.

While reverse_ssh can be used for legitimate penetration testing, its unauthorized presence on a vCenter server is a clear indicator of compromise. Security teams must actively monitor for unusual process execution and hunt for such backdoors across their server infrastructure.

What You Should Do

  • Apply Vendor Patches Immediately: Upgrade vulnerable vCenter appliances to the patched builds: 9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f.
  • Restrict Public Exposure: Remove vCenter management interfaces from direct internet exposure. Implement authenticated VPN access with multi-factor authentication (MFA) for all administrative access.
  • Execute Threat Hunting: Deploy YARA rules and endpoint detection signatures to scan vCenter binaries and temporary directories for reverse_ssh artifacts.
  • Audit Network Connections: Review egress network logs for any unusual or persistent outbound SSH sessions originating from vCenter management IP addresses.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

2.86 Billion Credentials Compromised, Enterprise Access for Sale

Next Post

WhatsApp launches new scam alert feature to combat social engineering

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
2.86 Billion Credentials Compromised, Enterprise Access for Sale
August 12, 2026
Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies
August 12, 2026
WindRelay Malware Uses SpyNote RAT, NFC Relay to Drain Accounts
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us