Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

A critical vulnerability in VMware vCenter has been exploited by threat actors, with over 360 victim IP addresses identified across 47 countries. The bug, tracked as CVE-2026-59310 (CVSS score of 9.8), is a directory traversal issue in the Syslog server that leads to remote code execution. This means a malicious actor can execute arbitrary code on the vulnerable system with just network access.

The vulnerability was patched by Broadcom on July 29, but it appears attackers have been exploiting it since August 3. Quirso, a rapid incident response company, has been tracking the campaign and identified over 340 victim IP addresses connecting to the attackers’ infrastructure within two days of exploitation. The five countries most affected are Germany, the US, Turkey, Iran, and France.

The exploitation is particularly concerning because it allows attackers to maintain an outbound control connection from the compromised systems, bypassing security controls that typically block inbound connections. Quirso notes a strong correlation between the time of disclosure and exploitation, suggesting the vulnerability disclosure may have triggered the campaign.

The attackers are using a reverse shell for persistent access, with Quirso releasing a generic YARA rule to identify the tool. However, this tool can also be used for legitimate penetration testing, so organizations with publicly accessible vCenter systems should validate any detections by looking for unauthorized installations and unexpected outbound connections and execution.

This vulnerability highlights the importance of patching critical vulnerabilities promptly, as well as having robust security controls in place to prevent exploitation. It also emphasizes the need for continuous monitoring and incident response capabilities to detect and respond quickly to emerging threats.

Organizations with VMware vCenter systems should review their security configurations and ensure all patches are up-to-date. Additionally, they should implement network segmentation, monitor for suspicious activity, and conduct regular vulnerability assessments to identify potential weaknesses. By taking proactive steps to address this vulnerability, organizations can reduce the risk of exploitation and minimize the impact of a potential breach.


Source: SecurityWeek — 2026-08-13