A newly patched critical flaw, CVE-2026-59310, in VMware vCenter Syslog Server is being actively exploited to install the reverse_ssh tool for persistence and remote access. QUIRSO says the campaign has hit 361 IP addresses across 47 countries, with rapid expansion soon after Broadcom released emergency fixes. #CVE-2026-59310 #VMwarevCenter #Broadcom #reverse_ssh #QUIRSO
Keypoints
- CVE-2026-59310 is a critical directory traversal flaw in VMware vCenter Syslog Server.
- Broadcom says an unauthenticated attacker with network access could execute arbitrary code.
- The vulnerability is being exploited to deploy the reverse_ssh framework.
- QUIRSO identified 361 victim IP addresses across 47 countries.
- The attack provides persistence and remote access through an outbound C2 channel.