Critical VMware vCenter Flaw Actively Exploited for Reverse SSH Access
A critical directory traversal vulnerability, **CVE-2026-59310**, in **VMware vCenter Syslog Server** is under active exploitation. Threat actors are leveraging this flaw to deploy reverse SSH tools, establishing persistence and remote access across hundreds of IP addresses globally, just days after the patch release.

A recently patched critical vulnerability, **CVE-2026-59310**, within the **VMware vCenter Syslog Server** is being actively exploited. Attackers are deploying a reverse SSH tool to gain persistence and remote access to compromised systems.
### Widespread Compromises Detected
Compromises have been identified across 361 IP addresses spanning 47 countries. More than half of these affected systems are located in Germany, the U.S., Turkey, Iran, and France.
**Broadcom** initially disclosed **CVE-2026-59310** on July 29, describing it as a critical directory traversal vulnerability. This flaw allows an unauthenticated attacker with network access to execute arbitrary code on the **vCenter Syslog Server**.
### Urgent Patching Recommended
**Broadcom** has not provided any workarounds or mitigations, strongly urging system administrators to apply the emergency update. The following **vCenter** releases address the security issue:
* **vCenter** 9.1: 9.1.0.0300
* **vCenter** 9.0: 9.0.2.0100
* **vCenter** 8.0: 8.0 U3k or 8.0 U2f, depending on the branch
**VMware vCenter** is a centralized management software crucial for controlling, monitoring, and configuring an organizationβs virtual infrastructure. Its broad control over critical systems makes it a frequent target for attackers seeking data theft or operational disruption.
### Rapid Exploitation Timeline
According to digital forensics and incident response (DFIR) company **QUIRSO**, compromised systems began connecting to attacker-controlled infrastructure on August 3, a mere five days after **Broadcom** disclosed the flaw and released the emergency patch.
The campaign expanded rapidly, with 151 new victim IP addresses observed on August 4. By the following day, the count of victim IPs reached 343. **QUIRSO** reported a total of 361 victim IPs by August 7.

### Reverse SSH for Persistence
After gaining access to vulnerable **vCenter** systems, the attackers deployed the open-source *reverse_ssh* framework. This tool establishes persistence and provides remote access, creating an outbound command-and-control (C2) channel that can bypass firewalls and other network security measures.
**QUIRSO** has released a generic [YARA rule](https://github.com/QUIRSO/QTRDetectionContent/blob/main/2026-08-10_reverse_ssh_generic.yar) to detect *reverse_ssh* client binaries. It's important to note that legitimate use of the tool will also trigger this alert.
Researchers at **QUIRSO** believe an advanced persistent threat (APT) actor is behind the exploitation activity. However, specific indicators are being withheld due to ongoing coordination with law enforcement authorities. **QUIRSO** plans a more detailed follow-up report covering the attackerβs infrastructure, techniques, persistence, and post-exploitation activity.