Critical VMware vCenter flaw exploited for remote access
Key Takeaways A critical directory traversal vulnerability, CVE-2026-59310, in VMware vCenter’s Syslog server component is under active exploitation. Advanced Persistent Threat (APT) actors are...
Key Takeaways
- A critical directory traversal vulnerability, CVE-2026-59310, in VMware vCenter’s Syslog server component is under active exploitation.
- Advanced Persistent Threat (APT) actors are leveraging this flaw to gain initial access and deploy reverse SSH backdoors.
- The vulnerability carries a CVSS score of 9.8, indicating maximum severity and remote code execution potential.
- Patches are available for vCenter versions 9.1, 9.0, and 8.0, and immediate application is mandatory as no workarounds exist.
Widespread Exploitation of Critical VMware vCenter Flaw for Remote Access
Cybersecurity analysts have uncovered an ongoing campaign targeting internet-exposed VMware vCenter instances. Threat actors are actively exploiting CVE-2026-59310, a severe vulnerability within the vCenter Syslog server, to establish initial footholds and deploy persistent reverse SSH tools for long-term access to compromised networks.
Table Of Content
The Vulnerability: CVE-2026-59310
Designated CVE-2026-59310, this critical flaw is a directory traversal vulnerability impacting the VMware vCenter Syslog server component. With a CVSS score of 9.8, it poses an extreme risk, allowing unauthenticated attackers with network access to an exposed vCenter instance to achieve remote code execution (RCE) with system-level privileges. Broadcom confirmed the absence of temporary workarounds or mitigations, making immediate patching essential to protect virtualized infrastructure.
Organizations running vulnerable vCenter versions are urged to apply the following remediated releases:
| Deployed Branch | Remediated Release | Vendor Advisory |
| VMware vCenter 9.1 | Version 9.1.0.0300 |
VMSA-2026-0006.1 |
| VMware vCenter 9.0 | Version 9.0.2.0100 |
VMSA-2026-0006.1 |
| VMware vCenter 8.0 | Version 8.0 U3k or 8.0 U2f |
VMSA-2026-0006.1 |
Rapid Exploitation Post-Disclosure
The window between public disclosure and active exploitation of CVE-2026-59310 was remarkably short. Broadcom issued its security advisory, VMSA-2026-0006, on July 29, 2026. Just five days later, on August 3, QUIRSO first detected compromised systems communicating with attacker-controlled command-and-control (C2) infrastructure.
Exploitation efforts escalated quickly. On August 4, an additional 151 victim IP addresses were observed connecting to C2 infrastructure. By August 5, approximately 95 percent of the 361 identified victim systems had already been compromised. This rapid timeline underscores the aggressive nature of threat actors in scanning for and exploiting newly disclosed vulnerabilities.
Global Impact and Attacker Tooling
Telemetry data indicates that compromised systems are geographically dispersed across 47 countries. More than half of the identified victim IP addresses are concentrated in five nations:
- Germany: 55 unique IPs
- United States: 41 unique IPs
- Turkey: 38 unique IPs
- Iran: 26 unique IPs
- France: 25 unique IPs
Following successful exploitation of the vCenter Syslog service, attackers are deploying reverse_ssh, an open-source SSH-based reverse-shell tool written in Go. This tool grants attackers robust post-exploitation capabilities, including:
- Automated Connect-Backs: Enables periodic outbound SSH connections to maintain remote channels.
- Port Forwarding: Facilitates local and remote dynamic port forwarding for lateral movement across internal subnets.
- File Transfer: Built-in SCP/SFTP capabilities simplify the staging and exfiltration of sensitive virtual machine files.
- Firewall Evasion: Establishes outbound control connections on standard ports, often bypassing inbound perimeter firewall rules.
While reverse_ssh can be used for legitimate penetration testing, its unauthorized presence on a vCenter server is a clear indicator of compromise. Security teams must actively monitor for unusual process execution and hunt for such backdoors across their server infrastructure.
What You Should Do
- Apply Vendor Patches Immediately: Upgrade vulnerable vCenter appliances to the patched builds:
9.1.0.0300,9.0.2.0100,8.0 U3k, or8.0 U2f. - Restrict Public Exposure: Remove vCenter management interfaces from direct internet exposure. Implement authenticated VPN access with multi-factor authentication (MFA) for all administrative access.
- Execute Threat Hunting: Deploy YARA rules and endpoint detection signatures to scan vCenter binaries and temporary directories for
reverse_sshartifacts. - Audit Network Connections: Review egress network logs for any unusual or persistent outbound SSH sessions originating from vCenter management IP addresses.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.