APT exploits patched VMware vCenter flaw

An APT actor is exploiting patched VMware vCenter flaw CVE-2026-59310 to run code and install a reverse SSH shell; more than 360 victim IPs in 47 countries identified.
An advanced persistent threat actor has exploited CVE-2026-59310 to run arbitrary code and deploy a reverse SSH shell on exposed VMware vCenter servers. Incident responders identified more than 360 victim IP addresses across 47 countries.
Broadcom released a patch for CVE-2026-59310 on July 29. The advisory describes the flaw as a directory traversal vulnerability in the vCenter Syslog server that can lead to remote code execution. The advisory states, “A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.” The vulnerability carries a CVSS score of 9.8.
Quirso reported active exploitation beginning on August 3 and observed over 340 victim IP addresses connecting to attacker infrastructure by August 5. The firm later identified more than 360 distinct IP addresses tied to the campaign, with roughly half located in Germany, the United States, Turkey, Iran and France. Quirso noted that some addresses belong to hosting providers, cloud networks or shared infrastructure, so the IP count does not directly equal the number of victim organizations.
According to Quirso’s analysis, attackers targeted web-accessible vCenter servers vulnerable to the Syslog directory traversal. After initial compromise, operators deployed the open-source reverse_ssh framework to establish outbound control channels. Using an outbound reverse shell allows control connections to bypass security controls that block inbound traffic.
Quirso released a generic YARA rule to detect reverse_ssh builds and advised validation of detections because the tool can be used for legitimate penetration testing. Organizations are instructed to search for unauthorized installations, unexpected outbound connections and signs of persistence when validating alerts.
System administrators should verify that the July 29 updates have been applied to vCenter instances and, where possible, remove unnecessary internet exposure. Administrators are also advised to review logs and network activity for unauthorized binaries, unexpected outbound SSH connections and persistence mechanisms.
VMware vCenter manages virtual infrastructure for many enterprises. Successful exploitation of a vCenter server can grant attackers access to virtual machines and administrative functions. Security teams are advised to follow vendor guidance and investigate any unusual activity on systems that could indicate exploitation or the presence of remote access tools.








