A critical VMware vCenter directory traversal flaw, tracked as CVE-2026-59310, is being actively exploited to achieve unauthenticated remote code execution through the vCenter Syslog Server component. Broadcom disclosed the issue and released emergency patches, warning that any attacker with network access to a vulnerable system could run arbitrary code. No workaround was provided, leaving patching and exposure reduction as the primary defenses for affected vCenter deployments.
Incident responders at QUIRSO reported exploitation beginning shortly after disclosure and said attackers are deploying the open-source reverse_ssh tool to establish outbound command-and-control channels and maintain persistence. The firm counted 361 victim IP addresses across 47 countries within days, while administrators on r/sysadmin amplified warnings to patch immediately and noted that internet-exposed or poorly isolated vCenter instances remain especially vulnerable. QUIRSO said the activity may be linked to an APT actor, though it has not publicly released supporting evidence and is coordinating indicators with law enforcement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By August 7, QUIRSO had identified 361 victim IP addresses across 47 countries in the VMware vCenter exploitation campaign. More than half of the identified victims were located in Germany, the United States, Turkey, Iran, and France.
QUIRSO reported that the number of victim IP addresses linked to exploitation of CVE-2026-59310 had reached 343. This showed rapid expansion of the campaign against vulnerable VMware vCenter systems.
QUIRSO reported seeing 151 new victim IP addresses tied to the VMware vCenter exploitation campaign. The observed compromises were associated with attacker use of reverse SSH access channels.
QUIRSO observed compromised VMware vCenter systems connecting to attacker-controlled infrastructure, indicating exploitation had begun. The activity involved deployment of the open-source reverse_ssh tool for persistence and remote access.
Broadcom disclosed the critical VMware vCenter Syslog Server directory traversal vulnerability CVE-2026-59310 and warned that an unauthenticated attacker with network access could execute arbitrary code. It released emergency updates for affected vCenter versions and provided no workarounds or mitigations.
A post on r/sysadmin warned administrators that the critical VMware vCenter flaw CVE-2026-59310 was under active exploitation, linking to BleepingComputer coverage and Broadcom's advisory. The discussion urged immediate patching and repeated reports of 361 compromised IPs across 47 countries.
QUIRSO said the global exploitation campaign targeting CVE-2026-59310 appeared to be the work of a single suspected advanced persistent threat actor. The firm also published a YARA rule to help defenders identify reverse_ssh builds used for post-exploitation persistence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcereddit.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.