Critical VMware vCenter RCE flaw exploited for reverse SSH access

Critical VMware vCenter RCE flaw exploited for reverse SSH access
A newly patched critical flaw, CVE-2026-59310, in VMware vCenter Syslog Server is being actively exploited to install the reverse_ssh tool for persistence and remote access. QUIRSO says the campaign has hit 361 IP addresses across 47 countries, with rapid expansion soon after Broadcom released emergency fixes. #CVE-2026-59310 #VMwarevCenter #Broadcom #reverse_ssh #QUIRSO

Keypoints

  • CVE-2026-59310 is a critical directory traversal flaw in VMware vCenter Syslog Server.
  • Broadcom says an unauthenticated attacker with network access could execute arbitrary code.
  • The vulnerability is being exploited to deploy the reverse_ssh framework.
  • QUIRSO identified 361 victim IP addresses across 47 countries.
  • The attack provides persistence and remote access through an outbound C2 channel.

Read More: https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/