A critical flaw in VMware vCenter is now being actively exploited in a global cyber campaign just days after the vulnerability was disclosed. The flaw, tracked as CVE-2026-59310, affects the vCenter Syslog Server and has a maximum CVSS score of 9.8. Broadcom disclosed the issue on July 29 and warned that an attacker with network access could exploit it to execute arbitrary code. The rapid attacks show how quickly major vulnerabilities can move from disclosure to real-world exploitation.

vmware-vcenter-security-vulnerability

The vulnerability is a directory traversal flaw, which means attackers can manipulate file paths to access locations they should not normally reach. Successful exploitation can lead to remote code execution on a vulnerable vCenter system. The risk is especially serious because VMware vCenter is used to centrally manage virtual machines, ESXi servers, configurations, and access permissions. A compromised vCenter can therefore provide an attacker with a powerful position inside an organization’s virtual infrastructure.

Security researchers at German incident-response company QUIRSO linked the activity to a suspected advanced persistent threat actor. Their investigation found affected systems began connecting to attacker-controlled infrastructure on August 3, only five days after Broadcom disclosed the vulnerability and released patches. The campaign then expanded quickly. Researchers observed 151 additional victim IP addresses on August 4, while 343 of the eventually identified addresses had appeared by August 5.

vmware-vcenter-directory-traversal-exploit

QUIRSO ultimately identified 361 unique IP addresses connected to the campaign across 47 countries. Germany, the United States, Turkey, Iran, and France were among the most heavily affected locations, together accounting for more than half of the observed IP addresses. However, researchers stressed that these numbers should not be treated as 361 confirmed organizations because some IP addresses can belong to cloud providers or shared hosting infrastructure. The figures show the campaign’s reach rather than an exact victim count.

The attackers also used the vulnerability for more than initial access. After compromising vulnerable vCenter systems, they deployed reverse_ssh, an open-source tool that can create an outbound SSH connection from a compromised machine. This gave the attackers a way to maintain remote access and establish a command-and-control channel. Reverse SSH can also help attackers bypass firewall restrictions because the connection is initiated from inside the affected environment rather than directly from an external system.

vmware-vcenter-server-cybersecurity

One important concern is that installing the update may not automatically remove an attacker who already gained access. QUIRSO said the threat actor was using reverse_ssh for persistence, meaning access could remain available even after the vulnerable software was patched. QUIRSO recommends investigating potentially compromised systems rather than assuming patching alone has solved the problem. They also released a YARA rule that can help identify reverse_ssh client binaries, although legitimate uses of the tool may trigger the detection.

Broadcom has released security updates for affected vCenter versions and says there are no workarounds for CVE-2026-59310. Fixed releases include vCenter 9.1.0.0300, 9.0.2.0100, and updates in the 8.0 branch, according to the company’s security advisory. Organizations running exposed vCenter systems should apply the update immediately and review their environments for unusual activity. Management interfaces should also be kept away from unnecessary internet exposure and tightly restricted through network controls.

vmware-vcenter-critical-flaw-cve-2026-59310

The campaign highlights a growing problem for organizations using common infrastructure software: attackers can move extremely quickly after a vulnerability becomes public. QUIRSO said activity peaked on August 4, but new victims were still being observed afterward, although at a slower rate. Researchers believe the timing is consistent with attackers developing an exploit after studying the public patch, though they have not confirmed how the actor obtained the capability. For defenders, fast patching, network isolation, and forensic checks must work together.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news