Critical VMware vCenter RCE flaw exploited for reverse SSH access
Reported exploitedVMware vCentervCenter Syslog ServerOur summary
An active exploitation campaign is targeting a critical directory traversal vulnerability, CVE-2026-59310, within the VMware vCenter Syslog Server to deploy a reverse SSH tool for persistence and remote access. Disclosed by Broadcom on July 29, the flaw enables unauthenticated attackers with network access to execute arbitrary code, impacting numerous organizations across 47 countries. To remediate the risk, administrators should immediately apply the emergency updates for VMware vCenter releases 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f, as no other workarounds are currently available.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.