Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

0
Critical
Vulnerability
Published: 08/13/2026 (08/13/2026, 09:06:40 UTC)
Source: SecurityWeek

Description

CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter's Syslog server that allows remote attackers with network access to execute arbitrary code. The flaw was patched by Broadcom on July 29, 2026, but attackers began exploiting it shortly after disclosure. An advanced persistent threat (APT) actor has used this vulnerability to gain persistent access to vulnerable vCenter servers by deploying a reverse SSH shell. Over 360 victim IP addresses across 47 countries have been identified, with significant concentration in Germany, the US, Turkey, Iran, and France. The exploitation campaign started around August 3, 2026, closely following the public disclosure. Organizations with publicly accessible vCenter servers are advised to verify detections carefully due to the dual-use nature of the reverse SSH tool used by attackers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 09:11:24 UTC

Technical Analysis

CVE-2026-59310 is a directory traversal vulnerability in the VMware vCenter Syslog server component that enables remote code execution by attackers with network access. The vulnerability received a CVSS score of 9.8 and was patched by Broadcom on July 29, 2026, alongside other VMware product fixes. Shortly after disclosure, an APT group exploited this flaw to deploy a reverse SSH shell (reverse_ssh) for persistent outbound control connections, bypassing inbound connection blocks. Quirso reported over 360 victim IPs across 47 countries, with exploitation activity starting on August 3, 2026. The attackers leveraged this vulnerability to maintain persistent access and evade typical security controls. A generic YARA rule was released to detect the reverse_ssh payload, but organizations should validate detections for unauthorized installations and unexpected outbound connections.

Potential Impact

The vulnerability allows remote attackers with network access to VMware vCenter servers to execute arbitrary code, potentially leading to full system compromise. The exploitation by an APT actor has resulted in persistent unauthorized access to compromised systems via a reverse SSH shell, enabling attackers to maintain control and evade inbound network security measures. The widespread exploitation across multiple countries indicates a significant operational impact on affected organizations.

Mitigation Recommendations

An official patch was released by Broadcom on July 29, 2026, addressing CVE-2026-59310. Organizations should apply this update immediately to remediate the vulnerability. For systems that may have been compromised, it is recommended to investigate for the presence of the reverse_ssh payload and unauthorized outbound connections. Due to the dual-use nature of the reverse_ssh tool, detections should be validated carefully. No additional generic mitigations are specified by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/","fetched":true,"fetchedAt":"2026-08-13T09:11:14.481Z","wordCount":1007}

Threat ID: 6a7d8a32bf8831d539f5663e

Added to database: 08/13/2026, 09:11:14 UTC

Last enriched: 08/13/2026, 09:11:24 UTC

Last updated: 08/13/2026, 09:51:49 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses