Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks. Tracked as CVE-2026-59310, the flaw is a maximum-severity directory-traversal vulnerability residing […] The post Hackers Activ
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
By Guru Baran
August 12, 2026
Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks.
Tracked as CVE-2026-59310, the flaw is a maximum-severity directory-traversal vulnerability residing in the VMware vCenter Syslog server component.
VMware vCenter Systems Exploited for Remote Access
Broadcom released a security advisory warning that unauthenticated attackers with network access to an exposed vCenter instance can exploit the vulnerability to achieve remote code execution (RCE) with system privileges.
Carrying a CVSS score of 9.8, the flaw represents an extreme operational risk for enterprise environments that expose management portals to the public internet or maintain unsegmented internal networks.
Broadcom confirmed that no temporary workarounds or mitigations exist for CVE-2026-59310, making immediate patching mandatory. Applying updates to fix critical VMware vulnerabilities is essential to protect virtualized infrastructure from takeover.
Deployed Branch Remediated Release Vendor Advisory
VMware vCenter 9.1 Version 9.1.0.0300 VMSA-2026-0006.1
VMware vCenter 9.0 Version 9.0.2.0100 VMSA-2026-0006.1
VMware vCenter 8.0 Version 8.0 U3k or 8.0 U2f VMSA-2026-0006.1
The transition from public disclosure to widespread exploitation occurred at an unusually rapid tempo. Broadcom initially published security advisory VMSA-2026-0006 on July 29, 2026.
QUIRSO first detected compromised systems communicating with attacker-controlled command-and-control (C2) infrastructure on August 3, just five calendar days post-disclosure.
Victim expansion 2026–08–03 to 2026–08–07 (Image Source: Medium)
Exploitation intensified rapidly on August 4, when 151 additional victim IP addresses were observed phoning home. By August 5, 343 out of the 361 total identified victim systems, approximately 95 percent, had already been compromised.
As detailed in the incident telemetry published in the QUIRSO report, this narrow timeframe indicates that threat actors moved aggressively to scan and exploit internet-facing appliances immediately after the vendor advisory was published.
Monitoring these trends is crucial as adversaries accelerate the exploitation of active vulnerabilities across enterprise software.
Top five victim countries of CVE-2026–59310 (Image Source: Medium)
Telemetry reveals that victim systems are spread across 47 countries, with more than half of the observed compromised IP addresses concentrated in five nations:
Germany: 55 unique IPs
United States: 41 unique IPs
Turkey: 38 unique IPs
Iran: 26 unique IPs
France: 25 unique IPs
Following successful exploitation of the vCenter Syslog service, the threat actor deploys reverse_sshAn open-source SSH-based reverse-shell tool written in Go to establish persistent access.
The tool equips attackers with robust post-exploitation capabilities:
Automated Connect-Backs: Periodically attempts outbound SSH connections to maintain remote channels.
Port Forwarding: Enables local and remote dynamic port forwarding for lateral movement across internal subnets.
File Transfer: Built-in SCP/SFTP capabilities simplify staging and exfiltrating sensitive virtual machine files.
Firewall Evasion: Establishes outbound control connections on standard ports, routinely bypassing inbound perimeter firewall rules.
While reverse_ssh is a dual-use penetration-testing tool, its unauthorized presence on a vCenter server is a strong indicator of compromise.
Security teams must monitor for unauthorized process execution and hunt for reverse shell backdoors across server infrastructure.
Organizations running VMware vCenter appliances should execute the following defensive measures immediately:
Apply Vendor Patches: Upgrade vulnerable vCenter appliances to patched builds (9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f).
Restrict Public Exposure: Remove vCenter management interfaces from direct internet exposure; require authenticated VPN access with multi-factor authentication (MFA).
Execute YARA Threat Hunting: Deploy YARA rules and endpoint detection signatures to scan vCenter binaries and temporary directories for reverse_ssh artifacts.
Audit Network Connections: Inspect egress network logs for unusual, persistent outbound SSH sessions originating from vCenter management IP addresses.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Tags
cyber security news
vulnerability
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket
Cyber Security News
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Cyber Security News
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Cyber Security
Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
Cyber Security News
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?