Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses observed across 47 countries.
This campaign reportedly began within days of the public disclosure and employs reverse SSH tooling to maintain remote access to compromised infrastructure.
Critical vCenter Exposure
CVE-2026-59310 is a directory-traversal flaw in VMware vCenter’s Syslog server. Broadcom assigned this vulnerability a maximum CVSS v3 score of 9.8 and warns that an attacker with network access can exploit it to execute arbitrary code.
The vendor has not provided any workaround, making prompt patching the only supported remediation.
The vulnerability was disclosed in Broadcom advisory VMSA-2026-0006 on July 29, 2026. An updated advisory, VMSA-2026-0006.1, includes fixes for vCenter versions 9.1, 9.0, and 8.0, specifically versions 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f.
According to QUIRSO GmbH’s Threat Research team, attacker-controlled infrastructure first received connections from affected systems on August 3, just five days after the initial disclosure.
The activity escalated rapidly, with 151 additional victim IPs observed the following day. By August 5, a total of 343 out of the 361 IPs had been identified.
Germany, the United States, Turkey, Iran, and France were the most affected countries, accounting for 185 observed IP addresses, slightly more than half of the campaign’s visible victim infrastructure.
Researchers caution that the count of victim IPs should not be taken as a direct representation of the number of impacted organizations. A single organization can operate multiple public-facing systems, and hosting, cloud services, and shared networks may group unrelated environments behind individual IP addresses.
Nevertheless, the rapid increase and widespread geographic distribution suggest extensive scanning and opportunistic exploitation of exposed vCenter deployments.
After gaining access, the suspected threat actor deployed reverse_ssh, an open-source, SSH-based reverse-shell framework. This software facilitates outbound connect-back channels, port forwarding, file transfers, multiple transports, and remote shell management.
These capabilities can be used legitimately in penetration testing but are also beneficial for malicious intruders.
For a compromised vCenter appliance, reverse SSH provides a resilient control path. Rather than relying on inbound access that may be constrained by perimeter firewalls or network segmentation, the affected system initiates an outbound connection to the attacker’s infrastructure. This can allow the intruder to regain remote access even after initial exploitation activities have ceased.
While the presence of reverse_ssh alone is not definitive proof of compromise, defenders should treat unauthorized binaries, unexpected outbound SSH-like sessions, and suspicious process executions on an unpatched vCenter Server as high-priority investigative leads.
Organizations should promptly identify all internet-accessible vCenter systems, verify the installed versions, and apply the relevant Broadcom updates. Broadcom’s response matrix also includes affected VMware Cloud Foundation, vSphere Foundation, and Telco Cloud products.
Security teams are advised to:
- Review vCenter logs and outbound network telemetry from August 3 onward.
- Search for unauthorized reverse_ssh binaries, persistence mechanisms, and unexplained SSH tunnels.
- Investigate unusual connections from vCenter appliances to unfamiliar external hosts.
- Restrict management-plane exposure and isolate potentially compromised appliances before conducting forensic investigations.
Given the short time frame between the vulnerability’s disclosure and its exploitation, unpatched internet-facing vCenter instances should be treated as potentially compromised until proven otherwise.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

