CVE-2026-59310: Active Exploit Hits 361 VMware vCenter Systems in 47 Countries
Broadcom VMware vCenter administrators are facing an active intrusion campaign targeting CVE-2026-59310, a critical directory-traversal vulnerability in the vCenter Syslog Server that carries a CVSS v3.1 score of 9.8.
Threat researchers at QUIRSO say they have identified 361 unique victim IP addresses across 47 countries, with evidence pointing to an advanced persistent threat (APT) exploiting the flaw to achieve code execution and establish persistent remote access.
CVE-2026-59310 is a path-traversal flaw in vCenter’s Syslog Server that allows a network-reachable attacker to execute arbitrary code without prior authentication.
Active Exploit Hits 361 VMware vCenter Systems
It was disclosed alongside CVE-2026-59309, an equally severe (CVSS 9.8) authentication-bypass bug in the VMware Directory Service, as part of Broadcom’s advisory VMSA-2026-0006, published July 29, 2026.
Both critical issues affect vCenter 9.1.x, 9.0.x, and 8.0 deployments, as well as vCenter instances embedded in Cloud Foundation, vSphere Foundation, and Telco Cloud products.
The risk is amplified by vCenter’s role as the central management plane for virtualized infrastructure. A successful compromise can give an intruder a foothold from which to pivot toward hosted workloads, harvest credentials, or manipulate administrative operations across an entire virtualization estate.
QUIRSO’s telemetry shows attackers moved quickly once the advisory went public. Affected systems began connecting to attacker-controlled infrastructure on August 3 just five calendar days after disclosure.
Activity then accelerated sharply: 151 additional victim IPs surfaced on August 4 alone, and by August 5, 343 of the 361 observed addresses roughly 95% had appeared.
QUIRSO notes that this tight correlation between disclosure and exploitation suggests the public advisory itself served as the initial signal for the campaign, though the attacker’s prior knowledge of the vulnerability cannot be ruled out.
Victim infrastructure is geographically dispersed. Germany, the United States, Turkey, Iran, and France rank as the five most-affected countries, together accounting for 185 of the 361 observed IPs.
QUIRSO cautions that these figures describe infrastructure, not verified organizations; a single company may control multiple addresses, while cloud, hosting, and shared networks can represent many unrelated tenants.
Following exploitation, investigators observed the deployment of reverse_ssh, an open-source SSH-based reverse-shell framework that offers automatic connect-back, port forwarding, file transfer, multiple transports, and remote shell management.
For an intruder, this creates an outbound control channel that is less likely to trip defenses tuned primarily to block unsolicited inbound connections.
QUIRSO stresses the tool is dual-use and legitimate in penetration testing, so its presence alone is not conclusive evidence of compromise; context such as unauthorized installation on a vulnerable appliance or unexpected SSH activity is what elevates it to a high-priority indicator.
Broadcom lists no workaround for CVE-2026-59310, making patching mandatory. Administrators should apply fixed builds: vCenter 9.1.0.0300, vCenter 9.0.2.0100, or the appropriate 8.0 U3k/U2f branch update, with Cloud Foundation 5.x and Telco Cloud products requiring vendor-specific remediation per KB449886.
Defenders should also restrict vCenter management access to approved administrative networks, audit outbound connections from vCenter appliances, and hunt for unexpected reverse_ssh binaries and SSH tunneling behavior.
QUIRSO has released a generic YARA rule for detecting reverse_ssh builds, though matches should be correlated with process execution, network telemetry, and change records before being treated as confirmed compromise.
Organizations detecting matching indicators should preserve evidence and begin incident-response triage immediately.
No Comment! Be the first one.