By Interestana AI Editorial — AI-drafted, human-overseen. How we report
VMware vCenter RCE Flaw Exploited for Reverse SSH Access
A critical remote code execution (RCE) vulnerability, identified as CVE-2026-59310, within VMware vCenter Syslog Server is currently being actively exploited in a widespread campaign. Threat actors are leveraging this flaw to deploy a reverse SSH tool, which establishes persistent remote access to compromised systems. This exploitation allows attackers to maintain a foothold within victim environments, bypassing traditional security measures and enabling further malicious activities. The vulnerability specifically targets the Syslog Server component of VMware vCenter, a widely used virtualization management platform. VMware addressed this critical issue by releasing security patches, urging customers to update their vCenter Server installations immediately to mitigate the risk of exploitation. The active exploitation indicates that attackers are aware of the vulnerability and are actively seeking out unpatched systems. The reverse SSH tool deployed by attackers creates an outbound SSH connection from the compromised server to an attacker-controlled server. This technique is particularly effective because outbound connections are often less scrutinized by network security devices than inbound connections, making it harder to detect and block. Once established, this reverse SSH tunnel provides attackers with a covert channel to execute commands, exfiltrate data, and move laterally within the network. The exploitation of CVE-2026-59310 highlights the ongoing threat posed by vulnerabilities in critical infrastructure management software. VMware vCenter is a foundational component for many organizations' IT operations, making its security paramount. The company's rapid response in patching the vulnerability is crucial, but the continued exploitation underscores the importance of timely patching and robust security monitoring. Security researchers have observed that the attackers are not only using this vulnerability for initial access but also for maintaining persistence, suggesting a sophisticated and targeted approach. The nature of the reverse SSH tool suggests that the attackers aim for long-term access to the compromised environments, potentially for espionage, data theft, or further disruption. Organizations using VMware vCenter are strongly advised to verify their patch status and implement additional security controls, such as network segmentation and intrusion detection systems, to further protect their environments from such sophisticated attacks. The exploitation of this vulnerability serves as a stark reminder of the persistent threats facing enterprise IT infrastructure and the critical need for proactive vulnerability management and rapid incident response.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.