bleeping-computer · Crawled Aug 13, 2026

Critical VMware vCenter RCE flaw exploited for reverse SSH access

Read original article ↗

AI Summary

A critical directory traversal vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to gain remote code execution. Attackers are deploying the open-source reverse_ssh framework to establish reverse SSH connections for persistence and remote access. Compromised systems have been observed connecting to attacker infrastructure starting August 3, with 361 victim IPs identified across 47 countries by August 7. The campaign is suspected to be conducted by an advanced persistent threat (APT) actor, though attribution remains unconfirmed.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.