Critical VMware vCenter RCE Flaw Exploited for Reverse SSH Access

Date:

A critical vulnerability (CVE-2026-59310) in VMware vCenter’s Syslog Server has been actively exploited, enabling attackers to gain remote access through reverse SSH connections. Discovered and disclosed by Broadcom on July 29, 2026, this flaw allows unauthenticated users with network access to execute arbitrary code on affected systems. The exploitation has been linked to at least 361 compromised servers across 47 countries, with significant concentrations noted in Germany, the United States, Turkey, Iran, and France.

Understanding CVE-2026-59310

This vulnerability is classified as a critical directory traversal flaw in the vCenter Syslog server. A successful attack could allow complete control over the server, leading to data theft or operational disruptions. The severity of this vulnerability stems from VMware vCenter’s role as a centralized management tool for virtual infrastructures, enabling monitoring and configuration of virtual machines and ESXi servers.

Broadcom has issued emergency updates for multiple vCenter versions, urging users to apply patches immediately due to the absence of workarounds. The affected versions include:

  • vCenter 9.1: 9.1.0.0300
  • vCenter 9.0: 9.0.2.0100
  • vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch

Active Exploitation Campaigns

The exploitation campaign escalated rapidly; within days of the vulnerability’s disclosure, attackers began penetrating systems, with connections to compromised infrastructure observed starting August 3. By August 4, the number of affected IP addresses surged to 151, reaching 343 by August 5, and ultimately totaling 361 by August 7.

According to digital forensics and incident response firm QUIRSO, the attackers deployed the open-source reverse_ssh framework to maintain persistence and establish remote access. This reverse SSH method facilitates outbound command-and-control channels, often bypassing network security measures such as firewalls, which presents a significant risk to any organization relying on vulnerable vCenter systems.

Detection and Mitigation Efforts

In response to this incident, QUIRSO has released a generic YARA rule aimed at detecting reverse_ssh client binaries. It’s crucial to note that legitimate use of the tool may also trigger detection alerts, complicating the identification of actual threats. Despite the identification of vulnerabilities, QUIRSO has expressed caution regarding attributing the attacks to specific persistent threat actors, citing the need for ongoing investigations and coordination with law enforcement.

What’s Next?

As the threat landscape evolves, organizations using VMware vCenter are urged to evaluate their security postures and ensure that all patches are promptly applied. The rapid adoption of reverse SSH connections by attackers highlights the need for robust monitoring and threat detection systems to prevent such exploitation in the future.

QUIRSO has indicated plans for further reporting that will detail the attackers’ infrastructure, techniques, and patterns of post-exploitation behavior. In the interim, organizations should remain vigilant and conduct thorough audits of their network environments to mitigate potential risks associated with this vulnerability.

As investigations continue, BleepingComputer has reached out to Broadcom for additional insights or responses concerning the ongoing exploitation activities, but no statements were available at the time of this publication.

This situation underscores the critical importance of adhering to cybersecurity best practices, particularly for organizations heavily reliant on virtual management tools like VMware vCenter.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...