Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence

TL;DR Summary
A critical vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to install the open-source reverse_ssh tool, establishing a persistent outbound C2 channel for remote access. Across 47 countries, 361 victim IPs have been identified, with Germany, the U.S., Turkey, Iran, and France most affected. VMware released an emergency patch; there are no official workarounds. Researchers from QUIRSO suspect an advanced persistent threat behind the campaign and note the attackers' activity began days after the vulnerability disclosure.
- Critical VMware vCenter RCE flaw exploited for reverse SSH access BleepingComputer
- Global Threat Campaign Hits Critical VMware vCenter Flaw Dark Reading
- Broadcom falls amid VMware security vulnerability reports Seeking Alpha
- Critical VMware vCenter Vulnerability in Attackers’ Crosshairs SecurityWeek
- Suspected APT Exploits Critical VMware vCenter Vulnerabilities in 47 Countries Hackread
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
3 min
vs 4 min read
Condensed
89%
704 → 79 words
Want the full story? Read the original article
Read on BleepingComputer