VMware vCenter Flaw Exploited Within Days of Patch Release
VMware vCenter Server is centralised management software that IT teams use to control entire fleets of virtual machines and servers from one place. According to Bleeping Computer, a critical flaw in its Syslog component is being actively exploited in the wild.
The vulnerability, CVE-2026-59310, is a directory traversal flaw (a weakness that lets an attacker navigate to files on a server they are not permitted to access) in vCenter's Syslog server. An attacker with basic network access, no login required, can trigger it to run any code they choose.
Broadcom disclosed and patched the flaw on July 29. By August 3, attackers were already in. By August 5, over 340 compromised servers had connected to attacker-controlled infrastructure. The final count reached 361 victim IP addresses across 47 countries.
Once inside, the attackers deployed reverse_ssh, an open-source tool that creates an outbound connection back to the attacker. Because the connection goes out rather than in, it slips past firewalls watching for incoming threats.
Incident response firm QUIRSO believes an advanced persistent threat (APT) group is behind the campaign. Broadcom has released no workarounds. A patch is the only fix.
What to do: If your organisation runs VMware vCenter, update immediately to version 9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f depending on your branch.
Sources

