Attackers begin exploiting critical VMware vCenter remote-code-execution flaw CVE-2026-59310

Attackers have started breaking into internet-exposed VMware vCenter servers using a newly patched critical flaw. The issue, CVE-2026-59310, is a CVSS 9.8 directory traversal bug in the vCenter Syslog server that can let a remote attacker with network access execute arbitrary code. Quirso says exploitation began around August 3 and observed more than 360 victim IP addresses across 47 countries, with attackers deploying the reverse_ssh tool to keep persistent outbound access.
Why it matters: Organizations that run VMware vCenter, especially systems reachable from the internet, should treat this as urgent and patch immediately, then check for reverse shells and unexpected outbound connections. vCenter is a high-value management system, so compromise can have broad downstream impact across virtualized infrastructure.

Sources

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
info@thehackernews.com (The Hacker News) 2026.08.19 84% relevant
It appears to cover the same VMware vCenter active exploitation event, likely as part of a roundup highlighting that exposed virtualization management servers need urgent attention.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
Ionut Arghire 2026.08.19 93% relevant
The article updates the vCenter story by noting CISA has now added CVE-2026-59310 to KEV and is calling for immediate patching after exploitation to drop an SSH reverse shell.
Critical VMware vCenter RCE flaw exploited for reverse SSH access
Bill Toulas 2026.08.13 96% relevant
This directly updates the same CVE-2026-59310 vCenter exploitation story with new operational details: exploitation began within days of disclosure, 361 victim IPs were observed across 47 countries, and attackers are deploying the reverse_ssh framework for persistence and outbound command-and-control access.
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Ionut Arghire 2026.08.13 100% relevant
This article appears to be the first item here establishing active exploitation of CVE-2026-59310 against VMware vCenter, including timing, observed victim scope, and attacker tradecraft.
← Back to all stories