• News/
  • bleepingcomputer-20260813164023

Critical VMware vCenter RCE flaw exploited for reverse SSH access

BleepingComputer
·
Bill Toulas
·
Published Aug 13, 2026
·
Updated

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France. Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that  could be exploited by an unauthenticated attacker with network access to execute arbitrary code. The vendor provides no workarounds or mitigations and urges system administrators to apply the emergency update and consult the FAQ post for additional information. The following vCenter releases address the security issue: VMware vCenter is a centralized management software for controlling, monitoring, and configuring an organization’s VMware virtual infrastructure, including virtual machines, ESXi servers, configurations, and access permissions. The product is a frequent target for its broad control over multiple critical systems. Attackers can use this access for data theft and operational disruptions. According to digital forensics and incident response (DFIR) company QUIRSO, compromised systems started to connect to attacker-controlled infrastructure on August 3, just five days after Broadcom disclosed the flaw and released the emergency patch. The campaign expanded quickly, with 151 new victim IP ...

Read full article

Affected Software

1 affected component
VMware vCenter Syslog Server

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in VMware vCenter Syslog Server that is being actively exploited for unauthorized remote access.

2

What security implications are discussed?

The exploitation of the vulnerability allows attackers to deploy a reverse SSH tool for persistence and remote access, posing significant security risks.

3

What specific vulnerability is mentioned in the article?

The article refers to the vulnerability identified as CVE-2026-59310.

4

How many IP addresses have been compromised according to the article?

The article reports compromises at 361 IP addresses across 47 countries.

5

What software is affected by this vulnerability?

The affected software is VMware vCenter Syslog Server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203