
Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence
A critical vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to install the open-source reverse_ssh tool, establishing a persistent outbound C2 channel for remote access. Across 47 countries, 361 victim IPs have been identified, with Germany, the U.S., Turkey, Iran, and France most affected. VMware released an emergency patch; there are no official workarounds. Researchers from QUIRSO suspect an advanced persistent threat behind the campaign and note the attackers' activity began days after the vulnerability disclosure.