Attackers have started breaking into internet-exposed VMware vCenter servers using a newly patched critical flaw. The issue, CVE-2026-59310, is a CVSS 9.8 directory traversal bug in the vCenter Syslog server that can let a remote attacker with network access execute arbitrary code. Quirso says exploitation began around August 3 and observed more than 360 victim IP addresses across 47 countries, with attackers deploying the reverse_ssh tool to keep persistent outbound access.
Why it matters: Organizations that run VMware vCenter, especially systems reachable from the internet, should treat this as urgent and patch immediately, then check for reverse shells and unexpected outbound connections. vCenter is a high-value management system, so compromise can have broad downstream impact across virtualized infrastructure.
info@thehackernews.com (The Hacker News)
2026.08.19
84% relevant
It appears to cover the same VMware vCenter active exploitation event, likely as part of a roundup highlighting that exposed virtualization management servers need urgent attention.
Ionut Arghire
2026.08.19
93% relevant
The article updates the vCenter story by noting CISA has now added CVE-2026-59310 to KEV and is calling for immediate patching after exploitation to drop an SSH reverse shell.
Bill Toulas
2026.08.13
96% relevant
This directly updates the same CVE-2026-59310 vCenter exploitation story with new operational details: exploitation began within days of disclosure, 361 victim IPs were observed across 47 countries, and attackers are deploying the reverse_ssh framework for persistence and outbound command-and-control access.
Ionut Arghire
2026.08.13
100% relevant
This article appears to be the first item here establishing active exploitation of CVE-2026-59310 against VMware vCenter, including timing, observed victim scope, and attacker tradecraft.
← Back to all stories