Cyber attackers have begun leveraging a critical vulnerability in VMware vCenter, as reported by the cybersecurity firm Quirso. This flaw, identified as CVE-2026-59310, was initially addressed by Broadcom on July 29, alongside other security issues in various VMware products.
Details of the Vulnerability
The vulnerability, with a CVSS score of 9.8, is a directory traversal bug in the Syslog server that could be exploited for remote code execution. According to Broadcom, attackers with network access to vCenter can potentially execute arbitrary code by exploiting this flaw.
Quirso observed that an advanced persistent threat (APT) group is actively targeting web-accessible VMware vCenter servers that remain susceptible to CVE-2026-59310. The attackers utilize a reverse shell to gain persistent access to these systems.
Global Impact and Exploitation
Quirso’s analysis revealed that more than 360 victim IP addresses, spanning 47 countries, have been compromised. Notably, half of these IPs are concentrated in Germany, the United States, Turkey, Iran, and France. However, the cybersecurity firm notes that IP addresses might not directly map to specific organizations since they often represent shared infrastructure or cloud networks.
The exploitation campaign began shortly after the vulnerability was disclosed, with over 340 IP addresses engaging with the attackers’ infrastructure by August 5. Quirso suggests that the public disclosure of the vulnerability likely triggered the campaign’s initiation.
Mitigation and Recommendations
Post-compromise, attackers have been deploying the open-source SSH reverse shell framework, reverse_ssh, to maintain communication with infected systems. This tactic helps them circumvent security measures that typically block inbound connections.
To aid in identifying these attacks, Quirso released a generic YARA rule designed to detect reverse_ssh builds. Organizations with exposed vCenter systems are advised to verify any detections by checking for unauthorized installations and unexpected outbound connections or activity.
The ongoing situation underscores the critical need for organizations to promptly apply security patches and monitor their systems for any signs of compromise to mitigate the risks associated with such vulnerabilities.
