VMware vCenter Users Warned of Critical Flaw Exploitation for Reverse SSH Access
A critical vulnerability (CVE-2026-59310) in VMware vCenter’s Syslog Server has been actively exploited by attackers to gain persistence and remote access to compromised systems. The issue, patched on July 29, is being used to deploy a reverse SSH tool, which allows the threat actors to bypass network security measures and maintain control over affected networks.
The exploitation campaign appears to be widespread, with more than 360 IP addresses in 47 countries found to have been compromised, including significant numbers of systems in Germany, the US, Turkey, Iran, and France. The rapid expansion of the campaign suggests that attackers are actively scanning for vulnerable vCenter systems and quickly exploiting the flaw.
VMware’s vCenter is a centralized management software used to control and monitor VMware virtual infrastructure, providing broad access to critical systems such as virtual machines and ESXi servers. As a result, it has become a frequent target for attackers seeking to compromise entire networks or disrupt operations. The exploitation of CVE-2026-59310 highlights the importance of timely patching and vigilance in protecting against advanced threats.
Attackers have been observed deploying the open-source reverse_ssh framework on compromised systems, establishing an outbound command-and-control channel that can bypass firewalls and other security measures. This allows them to maintain persistence and gain remote access to affected networks, making it essential for administrators to apply the emergency update as soon as possible.
QUIRSO, a digital forensics and incident response company, has identified 361 victim IPs across various countries and is tracking the campaign closely. They have released a generic YARA rule that detects reverse_ssh client binaries, although legitimate use of the tool also triggers an alert. QUIRSO plans to release a more detailed follow-up report on the attacker’s infrastructure, techniques, persistence, and post-exploitation activity.
Administrators should immediately apply the latest security update for vCenter (vCenter 9.1: 9.1.0.0300, vCenter 9.0: 9.0.2.0100, or vCenter 8.0: 8.0 U3k or 8.0 U2f) and ensure that all systems are updated to the latest version. This critical vulnerability underscores the importance of proactive security measures and timely patching in protecting against advanced threats.
In practical terms, this means that administrators should:
* Regularly review system logs for suspicious activity
* Ensure that all vCenter systems are patched with the latest updates
* Implement robust network segmentation to limit lateral movement
* Monitor for unusual SSH connections or traffic patterns
By taking these steps, organizations can mitigate the risk of exploitation and maintain their security posture in the face of evolving threats.
Source: Bleeping Computer — 2026-08-13