Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoiners Warned Of Wrench Attacks After Tax Authority Leak

    August 15, 2026

    Microplastics Found in Mexican Howler Monkeys Living in a UNESCO Biosphere Reserve

    August 15, 2026

    Deadly earthquake strikes Indonesia and triggers mass evacuations

    August 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoiners Warned Of Wrench Attacks After Tax Authority Leak
    • Microplastics Found in Mexican Howler Monkeys Living in a UNESCO Biosphere Reserve
    • Deadly earthquake strikes Indonesia and triggers mass evacuations
    • A RAMageddon guide to back-to-school laptop shopping
    • Hackers Exploiting Unpatched GeoServer Zero-Day
    • Crypto Biz: Bitcoin ETFs Rebound as Crypto Miners Extend AI Pivot
    • The Atlantic Ocean can handle more warming than expected — with one big catch
    • How Similar Is the Iran War to Vietnam?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 15, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.

    Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France.

    Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that  could be exploited by an unauthenticated attacker with network access to execute arbitrary code.

    image

    The vendor provides no workarounds or mitigations and urges system administrators to apply the emergency update and consult the FAQ post for additional information. The following vCenter releases address the security issue:

    • vCenter 9.1: 9.1.0.0300
    • vCenter 9.0: 9.0.2.0100
    • vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch

    VMware vCenter is a centralized management software for controlling, monitoring, and configuring an organization’s VMware virtual infrastructure, including virtual machines, ESXi servers, configurations, and access permissions.

    The product is a frequent target for its broad control over multiple critical systems. Attackers can use this access for data theft and operational disruptions.

    According to digital forensics and incident response (DFIR) company QUIRSO, compromised systems started to connect to attacker-controlled infrastructure on August 3, just five days after Broadcom disclosed the flaw and released the emergency patch.

    The campaign expanded quickly, with 151 new victim IP addresses being observed on August 4. By the next day, the count of victim IPs reached 343.

    However, QUIRSO notes that it identified a total of 361 victim IPs by August 7.

    Caption

    After obtaining access to vulnerable vCenter systems, the attacker deployed the open-source reverse_ssh framework to establish persistence and gain remote access.

    The reverse SSH connection provides an outbound command-and-control (C2) channel and can also help bypass firewalls or other network security measures.

    QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries. It should be noted that legitimate use of the tool also triggers the alert.

    The researchers believe that an advanced persistent threat (APT) actor is behind the exploitation activity, although they provided no evidence to support this and are withholding specific indicators due to ongoing coordination with law enforcement authorities.

    QUIRSO plans a more detailed follow-up report that covers the attacker’s infrastructure, techniques, persistence, and post-exploitation activity.

    BleepingComputer has contacted Broadcom for a statement on QUIRSO’s findings, but we have not received a response by publication time.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    access critical Exploited Flaw RCE reverse SSH vCenter VMware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers Exploiting Unpatched GeoServer Zero-Day

    RingCentral data breach exposed info of 1.6 million accounts

    14,000 Trezor Customers Impacted by Data Breach at ShipMonk

    Max severity SAP Commerce Cloud flaw now targeted in attacks

    How Anthropic plans to watermark Claude’s AI-generated text

    As Trump Expands Hunting and Fishing Access on Wildlife Refuges, What Will the Impact Be?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoiners Warned Of Wrench Attacks After Tax Authority Leak

    August 15, 2026

    Microplastics Found in Mexican Howler Monkeys Living in a UNESCO Biosphere Reserve

    August 15, 2026

    Deadly earthquake strikes Indonesia and triggers mass evacuations

    August 15, 2026

    A RAMageddon guide to back-to-school laptop shopping

    August 15, 2026
    Latest Posts

    Meta just created a moderation nightmare for its smart glasses

    July 26, 2026

    Maga’s creepy baby obsession won’t solve the fertility crisis

    July 26, 2026

    France battles fire ‘whirlwinds’ as another 55,000 evacuated

    July 26, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoiners Warned Of Wrench Attacks After Tax Authority Leak

    August 15, 2026

    Microplastics Found in Mexican Howler Monkeys Living in a UNESCO Biosphere Reserve

    August 15, 2026

    Deadly earthquake strikes Indonesia and triggers mass evacuations

    August 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.