Critical VMware vCenter RCE flaw exploited for reverse SSH access
A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries.
Intelligence analysis by Llama

A recently patched critical vulnerability in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries.
Imagine you have a super powerful tool that can control many things in your house, like lights, locks, and cameras. But, if someone gets access to that tool, they can do anything they want in your house. That's what's happening with the VMware vCenter vulnerability. Attackers are using it to get access to many systems and do bad things.
Analysis
Vulnerability Overview
A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server was recently patched by Broadcom. However, the vulnerability is being actively exploited by attackers to deploy a reverse SSH tool for persistence and remote access. The vulnerability allows an unauthenticated attacker with network access to execute arbitrary code.
Exploitation and Impact
Compromises have been identified at 361 IP addresses across 47 countries, with more than half located in Germany, the U.S., Turkey, Iran, and France. The attackers are using the reverse SSH tool to establish persistence and gain remote access to the compromised systems. This allows them to bypass firewalls or other network security measures and gain a foothold in the compromised systems.
Detection and Mitigation
QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries. However, it is essential to note that legitimate use of the tool also triggers the alert. The researchers believe that an advanced persistent threat (APT) actor is behind the exploitation activity, although they provided no evidence to support this and are withholding specific indicators due to ongoing coordination with law enforcement authorities.
Prevention and Patching
The vulnerability is addressed in the following vCenter releases: vCenter 9.1: 9.1.0.0300 vCenter 9.0: 9.0.2.0100 vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch. It is essential to apply the emergency update and consult the FAQ post for additional information.
Key points
- A critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited to deploy a reverse SSH tool for persistence and remote access.
- Compromises have been identified at 361 IP addresses across 47 countries.
- QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries.
- The vulnerability is addressed in the following vCenter releases: vCenter 9.1: 9.1.0.0300 vCenter 9.0: 9.0.2.0100 vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch.
If the attackers are caught and the vulnerability is patched, the compromised systems can be cleaned up, and the attackers will no longer have access. Additionally, the release of the YARA rule can help detect and prevent future attacks.
If the attackers are not caught, they can continue to use the vulnerability to gain access to more systems, causing significant damage and disruption. Additionally, the lack of evidence to support the APT actor's involvement may lead to a prolonged investigation, allowing the attackers to continue their activities.



