Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter's Syslog server that allows remote attackers with network access to execute arbitrary code. The flaw was patched by Broadcom on July 29, 2026, but attackers began exploiting it shortly after disclosure. An advanced persistent threat (APT) actor has used this vulnerability to gain persistent access to vulnerable vCenter servers by deploying a reverse SSH shell. Over 360 victim IP addresses across 47 countries have been identified, with significant concentration in Germany, the US, Turkey, Iran, and France. The exploitation campaign started around August 3, 2026, closely following the public disclosure. Organizations with publicly accessible vCenter servers are advised to verify detections carefully due to the dual-use nature of the reverse SSH tool used by attackers.
AI Analysis
Technical Summary
CVE-2026-59310 is a directory traversal vulnerability in the VMware vCenter Syslog server component that enables remote code execution by attackers with network access. The vulnerability received a CVSS score of 9.8 and was patched by Broadcom on July 29, 2026, alongside other VMware product fixes. Shortly after disclosure, an APT group exploited this flaw to deploy a reverse SSH shell (reverse_ssh) for persistent outbound control connections, bypassing inbound connection blocks. Quirso reported over 360 victim IPs across 47 countries, with exploitation activity starting on August 3, 2026. The attackers leveraged this vulnerability to maintain persistent access and evade typical security controls. A generic YARA rule was released to detect the reverse_ssh payload, but organizations should validate detections for unauthorized installations and unexpected outbound connections.
Potential Impact
The vulnerability allows remote attackers with network access to VMware vCenter servers to execute arbitrary code, potentially leading to full system compromise. The exploitation by an APT actor has resulted in persistent unauthorized access to compromised systems via a reverse SSH shell, enabling attackers to maintain control and evade inbound network security measures. The widespread exploitation across multiple countries indicates a significant operational impact on affected organizations.
Mitigation Recommendations
An official patch was released by Broadcom on July 29, 2026, addressing CVE-2026-59310. Organizations should apply this update immediately to remediate the vulnerability. For systems that may have been compromised, it is recommended to investigate for the presence of the reverse_ssh payload and unauthorized outbound connections. Due to the dual-use nature of the reverse_ssh tool, detections should be validated carefully. No additional generic mitigations are specified by the vendor advisory.
Affected Countries
Germany, United States, Turkey, Iran, France
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Description
CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter's Syslog server that allows remote attackers with network access to execute arbitrary code. The flaw was patched by Broadcom on July 29, 2026, but attackers began exploiting it shortly after disclosure. An advanced persistent threat (APT) actor has used this vulnerability to gain persistent access to vulnerable vCenter servers by deploying a reverse SSH shell. Over 360 victim IP addresses across 47 countries have been identified, with significant concentration in Germany, the US, Turkey, Iran, and France. The exploitation campaign started around August 3, 2026, closely following the public disclosure. Organizations with publicly accessible vCenter servers are advised to verify detections carefully due to the dual-use nature of the reverse SSH tool used by attackers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59310 is a directory traversal vulnerability in the VMware vCenter Syslog server component that enables remote code execution by attackers with network access. The vulnerability received a CVSS score of 9.8 and was patched by Broadcom on July 29, 2026, alongside other VMware product fixes. Shortly after disclosure, an APT group exploited this flaw to deploy a reverse SSH shell (reverse_ssh) for persistent outbound control connections, bypassing inbound connection blocks. Quirso reported over 360 victim IPs across 47 countries, with exploitation activity starting on August 3, 2026. The attackers leveraged this vulnerability to maintain persistent access and evade typical security controls. A generic YARA rule was released to detect the reverse_ssh payload, but organizations should validate detections for unauthorized installations and unexpected outbound connections.
Potential Impact
The vulnerability allows remote attackers with network access to VMware vCenter servers to execute arbitrary code, potentially leading to full system compromise. The exploitation by an APT actor has resulted in persistent unauthorized access to compromised systems via a reverse SSH shell, enabling attackers to maintain control and evade inbound network security measures. The widespread exploitation across multiple countries indicates a significant operational impact on affected organizations.
Mitigation Recommendations
An official patch was released by Broadcom on July 29, 2026, addressing CVE-2026-59310. Organizations should apply this update immediately to remediate the vulnerability. For systems that may have been compromised, it is recommended to investigate for the presence of the reverse_ssh payload and unauthorized outbound connections. Due to the dual-use nature of the reverse_ssh tool, detections should be validated carefully. No additional generic mitigations are specified by the vendor advisory.
Affected Countries
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/","fetched":true,"fetchedAt":"2026-08-13T09:11:14.481Z","wordCount":1007}
Threat ID: 6a7d8a32bf8831d539f5663e
Added to database: 08/13/2026, 09:11:14 UTC
Last enriched: 08/13/2026, 09:11:24 UTC
Last updated: 08/13/2026, 09:51:49 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.