discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries.

By Bill Toulas·Aug 13·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Critical VMware vCenter RCE flaw exploited for reverse SSH access
Image: bleepingcomputer.com

A recently patched critical vulnerability in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries.

Why it matters

This story matters because it highlights the importance of patching critical vulnerabilities in a timely manner to prevent exploitation by attackers.

Imagine you have a super powerful tool that can control many things in your house, like lights, locks, and cameras. But, if someone gets access to that tool, they can do anything they want in your house. That's what's happening with the VMware vCenter vulnerability. Attackers are using it to get access to many systems and do bad things.

Analysis

Vulnerability Overview

A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server was recently patched by Broadcom. However, the vulnerability is being actively exploited by attackers to deploy a reverse SSH tool for persistence and remote access. The vulnerability allows an unauthenticated attacker with network access to execute arbitrary code.

Exploitation and Impact

Compromises have been identified at 361 IP addresses across 47 countries, with more than half located in Germany, the U.S., Turkey, Iran, and France. The attackers are using the reverse SSH tool to establish persistence and gain remote access to the compromised systems. This allows them to bypass firewalls or other network security measures and gain a foothold in the compromised systems.

Detection and Mitigation

QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries. However, it is essential to note that legitimate use of the tool also triggers the alert. The researchers believe that an advanced persistent threat (APT) actor is behind the exploitation activity, although they provided no evidence to support this and are withholding specific indicators due to ongoing coordination with law enforcement authorities.

Prevention and Patching

The vulnerability is addressed in the following vCenter releases: vCenter 9.1: 9.1.0.0300 vCenter 9.0: 9.0.2.0100 vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch. It is essential to apply the emergency update and consult the FAQ post for additional information.

Key points

  • A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access.
  • Compromises have been identified at 361 IP addresses across 47 countries.
  • QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries.
  • The vulnerability is addressed in the following vCenter releases: vCenter 9.1: 9.1.0.0300 vCenter 9.0: 9.0.2.0100 vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch.
The Upside

If the attackers are caught and the vulnerability is patched, the compromised systems can be cleaned up, and the attackers will no longer have access. Additionally, the release of the YARA rule can help detect and prevent future attacks.

The Downside

If the attackers are not caught, they can continue to use the vulnerability to gain access to more systems, causing significant damage and disruption. Additionally, the lack of evidence to support the APT actor's involvement may lead to a prolonged investigation, allowing the attackers to continue their activities.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsvmwarevcenterrcereverse-sshexploitationpatchingvulnerability

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Aug 13, 2026

Source

bleepingcomputer.com

Share

Topics

vmwarevcenterrcereverse-sshexploitationpatchingvulnerability

Related

More from this desk

Aug 13·bleepingcomputer.com

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet maker Trezor disclosed a data breach affecting nearly 14,000 customers after its shipping provider ShipMonk was hacked via a Metabase vulnerability.

Aug 13·bleepingcomputer.com

Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

The article discusses the challenge of vetting AI code, particularly in open-source software, due to the rapid generation of dependencies by AI coding assistants. This has led to a vulnerability known as slopsquatting, where attackers register dummy package names on publi…

Aug 13·bleepingcomputer.com

White House Taps Security Firms for Offensive Hack-Back Operations

The White House has signed a national security presidential memorandum that enables private security companies to apply for approval to hack foreign cybercrime organizations. The program will be overseen by executive directors designated by the Justice and Homeland Securi…

Aug 13·bleepingcomputer.com

WhatsApp rolls out new feature that flags potential scam messages

WhatsApp has started rolling out a new optional feature called Scam Alert, which uses a local machine learning model to warn users about potential scam messages. The model is trained on scam conversations reported by users and checks incoming messages from non-contacts fo…