A widespread cyberattack campaign is actively exploiting a critical vulnerability in VMware vCenter Server, tracked as CVE-2026-59310. The flaw, which has a CVSS score of 9.8, allows an unauthenticated attacker with network access to achieve remote code execution (RCE). A suspected Advanced Persistent Threat (APT) group began exploiting the vulnerability on August 3, 2026, just five days after Broadcom released a patch. The attackers have already compromised at least 361 systems across 47 countries, deploying an open-source reverse SSH shell to establish persistent, fire-wall-bypassing access. Given the criticality of vCenter in managing enterprise virtual infrastructure, this vulnerability poses a severe risk, and immediate patching is required.
CVE-2026-59310 is a directory traversal vulnerability in the vCenter Syslog server component. An unauthenticated attacker with network access to the vCenter appliance can send a specially crafted request to exploit this flaw. Successful exploitation allows the attacker to write files to arbitrary locations on the server's filesystem, which can then be leveraged to execute arbitrary code with the privileges of the vCenter service.
The vulnerability affects multiple versions of VMware vCenter Server. Broadcom addressed the flaw in its VMSA-2026-0006 advisory. All organizations running unpatched versions are considered vulnerable. The advisory provides specific details on affected versions and the required updates.
The vulnerability is under active exploitation. Security firm QUIRSO reported that attacks began on August 3, 2026. The campaign is widespread, with victim IPs identified in 47 countries, including significant concentrations in Germany, the United States, Turkey, Iran, and France. After gaining initial access by exploiting CVE-2026-59310, the attackers have been observed deploying reverse_ssh, an open-source tool that creates a persistent SSH reverse shell. This allows the threat actor to maintain access to the compromised system via an outbound connection, which is often less scrutinized and can bypass perimeter firewalls.
A compromise of vCenter Server is a catastrophic event for any organization using VMware virtualization. The vCenter appliance is a central control plane for managing ESXi hosts, virtual machines, storage, and networking. An attacker with RCE on vCenter can:
The use of a reverse shell for persistence indicates the attacker's intent to maintain long-term access for espionage or to prepare for a more disruptive follow-on attack.
The following patterns may help identify vulnerable or compromised systems:
reverse_ssh/var/log/vmware/, /tmp/../) in requests to the vCenter Syslog service. This is a form of D3FEND's Network Traffic Analysis (D3-NTA).reverse_ssh tool, unexpected outbound connections, and unauthorized files or scripts on the vCenter appliance.New technical details on persistence, including cron job usage and MITRE ATT&CK mapping, enhance understanding of the attack.
The primary and most effective mitigation is to apply the security updates from Broadcom as soon as possible.
Mapped D3FEND Techniques:
Restrict network access to the vCenter management interface to a dedicated and secured management network, preventing exposure to the broader network or internet.
Mapped D3FEND Techniques:
Implement strict egress filtering to block unexpected outbound connections from the vCenter appliance, which could prevent reverse shells from connecting back to the C2 server.
Mapped D3FEND Techniques:
Broadcom (VMware) discloses and patches CVE-2026-59310.
Active exploitation of CVE-2026-59310 begins, as reported by QUIRSO.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.