Critical VMware vCenter vulnerability exploited to deploy reverse SSH tools
A recently patched critical vulnerability in VMware vCenter Syslog Server, tracked as CVE-2026-59310, is being actively exploited to install reverse SSH tools that provide attackers with persistence and remote access.
Incident responders have identified compromised systems linked to 361 IP addresses across 47 countries. More than half of the affected IP addresses are located in Germany, the United States, Turkey, Iran, and France.
Broadcom disclosed CVE-2026-59310 on July 29, describing it as a critical directory traversal vulnerability in vCenter Syslog Server. An unauthenticated attacker with network access to a vulnerable system could exploit the flaw to execute arbitrary code.
Broadcom has not provided workarounds or additional mitigations. System administrators are urged to apply the emergency update and review the vendor’s security advisory FAQ for further information. The vulnerability is fixed in the following vCenter releases:
- vCenter 9.1: 9.1.0.0300
- vCenter 9.0: 9.0.2.0100
- vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the product branch
VMware vCenter is a centralized management platform used to control, monitor, and configure VMware virtual infrastructure. It manages virtual machines, ESXi hosts, system configurations, permissions, and other critical resources.
Because vCenter provides extensive control over enterprise virtualization environments, it is a high-value target for attackers. Successful exploitation could allow threat actors to steal sensitive data, establish persistence, move through the network, or disrupt business operations.
According to digital forensics and incident response firm QUIRSO, compromised vCenter systems began connecting to attacker-controlled infrastructure on August 3—only five days after Broadcom disclosed CVE-2026-59310 and released an emergency patch.
The campaign expanded quickly. Researchers observed 151 new victim IP addresses on August 4. By the following day, the number of identified victim IPs had increased to 343.
In a QUIRSO report, the company said it had identified 361 victim IP addresses as of August 7.

After compromising a vulnerable vCenter system, the attackers deployed reverse_ssh, a framework designed to establish persistence and maintain remote access.
Reverse SSH connections create an outbound command-and-control (C2) channel. They can also help attackers bypass firewalls and other network security controls because the compromised system initiates the connection to the remote server.
QUIRSO has published YARA rules to help defenders detect the reverse_ssh client binary. However, the researchers warned that legitimate use of the tool may also generate alerts, so security teams should validate detections before taking action.
Researchers suspect that advanced persistent threat (APT) actors may be responsible for the exploitation activity. However, they said there is currently no evidence confirming the identity of the attackers. Specific indicators of compromise are being withheld while QUIRSO coordinates with law enforcement.
QUIRSO plans to release additional reports detailing the attackers’ infrastructure, techniques, persistence mechanisms, and post-exploitation activity.
BleepingComputer contacted Broadcom for comment on QUIRSO’s findings but had not received a response at the time of publication.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




