Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Critical VMware vCenter Vulnerability Exploited by Attackers, Widespread Impact Reported

A critical vulnerability in VMware’s vCenter product has been exploited by attackers, with over 360 victim IP addresses identified across 47 countries. The bug, tracked as CVE-2026-59310, allows malicious actors to execute arbitrary code on affected systems, highlighting the need for swift action to mitigate this risk.

The issue was patched by Broadcom on July 29, but it appears that attackers have been exploiting it since shortly after disclosure. Quirso, a rapid incident response company, has reported that an advanced persistent threat (APT) actor is behind the exploitation, using a reverse shell to maintain persistent access to compromised systems. The attack vector involves web-accessible VMware vCenter servers, with the attackers leveraging the directory traversal vulnerability in the Syslog server.

The scope of the attack is significant, with 47 countries affected and half of the victim IP addresses concentrated in just five countries: Germany, the US, Turkey, Iran, and France. However, Quirso notes that it’s difficult to determine the exact number of unique organizations impacted, as some IP addresses may belong to hosting providers or shared infrastructure.

The exploitation began on August 3, with a rapid increase in victim IP addresses connecting to the attackers’ infrastructure by August 5. The attackers dropped the open-source SSH reverse shell framework reverse_ssh to maintain control over compromised systems, which bypasses security controls that typically block inbound connections. Quirso has released a generic YARA rule for identifying reverse_ssh builds, advising organizations with publicly accessible vCenter systems to validate any detections and look for unauthorized installations or unexpected outbound connections.

The rapid exploitation of this vulnerability serves as a stark reminder of the importance of timely patching and vigilance in cybersecurity. Organizations with VMware vCenter deployments should prioritize applying the relevant patches and conducting thorough risk assessments to ensure their systems are secure. This incident also underscores the need for continuous monitoring and detection capabilities, particularly in environments where web-accessible servers are present.

In light of this attack, it’s essential for organizations to revisit their security controls and procedures, ensuring they can detect and respond effectively to similar threats. This includes implementing robust patch management practices, conducting regular vulnerability assessments, and maintaining up-to-date incident response plans. By taking proactive steps to secure their environments, organizations can minimize the risk of falling victim to such attacks in the future.


Source: SecurityWeek — 2026-08-13