A Critical VMware Flaw is Being Actively Exploited for Remote Access, With 361 Systems Compromised Across 47 Countries
A critical vulnerability in VMware vCenter Syslog Server has been spotted being exploited by attackers to gain remote access and persistence on compromised systems. The flaw, identified as CVE-2026-59310, was patched by Broadcom just last month, but it appears that malicious actors have already moved quickly to take advantage of the weakness.
According to digital forensics experts at QUIRSO, who have been tracking the campaign, over 360 IP addresses in 47 countries have been compromised, with a significant concentration in Germany, the US, Turkey, Iran, and France. The attackers are using the reverse SSH framework to establish persistence and gain remote access to the vulnerable systems, which can then be used for data theft or operational disruptions.
VMware vCenter is a centralized management software that provides control over multiple critical systems within an organization’s VMware virtual infrastructure. Its broad control makes it a frequent target for attackers, who can use this access to wreak havoc on organizations’ digital operations. The fact that the attackers have already compromised so many systems in such a short time suggests that they are using sophisticated tactics and techniques.
QUIRSO notes that the campaign began just five days after Broadcom disclosed the flaw and released an emergency patch, with 151 new victim IP addresses being observed on August 4 alone. By the next day, the count of victim IPs had reached 343, before eventually totaling 361 by August 7. The speed at which the attackers have moved suggests that they are likely an advanced persistent threat (APT) actor.
Once the attackers gain access to a vulnerable vCenter system, they deploy the open-source reverse SSH framework to establish persistence and gain remote access. This provides an outbound command-and-control channel and can also help bypass firewalls or other network security measures. QUIRSO has released a generic YARA rule that detects the client binaries of the reverse SSH tool, although it’s worth noting that legitimate use of the tool also triggers the alert.
While Broadcom has urged system administrators to apply the emergency update and consult the FAQ post for additional information, it appears that many organizations may still be vulnerable. The fact that attackers have already compromised so many systems highlights the importance of timely patching and vulnerability management in today’s threat landscape.
In light of this incident, it’s essential for organizations to prioritize the security of their VMware vCenter infrastructure by ensuring that all software is up-to-date with the latest patches. This includes applying the emergency update mentioned above and taking steps to detect and prevent potential exploitation attempts. By doing so, organizations can reduce the risk of falling victim to such attacks in the future.
Source: Bleeping Computer — 2026-08-13