Skip to content

Critical RCE Vulnerability in VMware vCenter (CVE-2026-59310) Actively Exploited for Reverse SSH Access

Bottom line: An already patched but actively exploited RCE vulnerability in VMware vCenter (CVE-2026-59310) is being used to establish reverse SSH access for persistent footholds on vSphere management servers.

A critical vulnerability in the VMware vCenter Syslog Server (CVE-2026-59310), patched only recently, is being exploited in an active attack campaign to grant attackers persistent remote access to affected systems via a reverse SSH tool. CISOs with VMware infrastructure should check their patch status immediately.

Affected is the Syslog Server component of VMware vCenter, which allows Remote Code Execution (RCE) via the vulnerability designated CVE-2026-59310. VMware has already released a patch for the flaw, yet security researchers are observing active exploitation of the vulnerability in the wild. Attackers are exploiting the flaw to plant a reverse SSH tool on compromised vCenter instances.

The reverse SSH tool is used by attackers to establish persistence, enabling them to maintain permanent remote access to the system even after initial attack vectors have been closed. vCenter servers typically manage an organization’s entire VMware vSphere infrastructure, including ESXi hosts and virtual machines. A successful compromise of a vCenter server therefore potentially grants attackers far-reaching access to the central management layer of the virtualization environment.

For CISOs, this creates an immediate need for action: since the vulnerability is already being actively exploited, the patch provided by VMware should be applied with priority if this has not already been done. It is also advisable to check your own vCenter instances for indicators of compromise, particularly unauthorized SSH connections or unusual outbound network connections from vCenter systems, which could indicate an already installed reverse SSH tool.


Source: www.bleepingcomputer.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: