Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Incidents: APT actors exploit VMware vCenter's CVE-2026-59310 (CVSS 9.8) for RCE, compromising 360+ IPs globally via reverse_ssh persistence.
Deep Analysis and Expert Commentary
The attack chain leverages a directory traversal flaw in vCenter's Syslog server, allowing unauthenticated RCE via network access. Post-compromise, attackers deploy reverse_ssh—a legitimate pentesting tool—to bypass inbound connection blocks, establishing stealthy command channels. The campaign's rapid scaling (340+ IPs in 3 days) suggests automated scanning or pre-existing target lists. Geographic clustering in five countries implies either strategic targeting or concentrated vulnerable deployments. Mitigation requires immediate patching, network segmentation for vCenter, and egress filtering to detect anomalous SSH connections. Organizations should correlate YARA alerts with unexpected process execution and outbound traffic patterns to avoid false positives from authorized red teams.
Action Items
- Patch VMware vCenter immediately to address CVE-2026-59310.
- Monitor for unexpected outbound SSH connections and reverse_ssh installations.
- Implement network segmentation to restrict vCenter server access.
Original Article Brief Intro
SecurityWeek · 2026-08-13 · Incidents: APT actors exploit VMware vCenter's CVE-2026-59310 (CVSS 9.8) for RCE, compromising 360+ IPs globally via reverse_ssh persistence.
Related Terms and Notes
CVE IDs
- CVE-2026-59310 — Critical directory traversal flaw in VMware vCenter Syslog server allowing RCE (CVSS 9.8).
Techniques / TTPs
- RCE
- reverse_ssh — Open-source SSH reverse shell tool used for persistent access, also employed in legitimate pentesting.
Context Notes
- APT
- APT campaign
- directory traversal
- remote code execution
- reverse shell
- reverse_ssh
- VMware
- VMware vCenter