← Back to Feed
Critical VMware vCenter RCE flaw exploited for reverse SSH access
CVE-2026-59310
August 13, 2026 · BleepingComputer · Severity: CRITICAL
A critical remote code execution vulnerability in VMware vCenter Syslog Server, tracked as CVE-2026-59310, is being actively exploited in a campaign that installs a reverse SSH tool for persistent remote access. Although the vulnerability has been patched, attackers are using it to gain RCE and maintain long-term access to compromised vCenter instances, emphasizing the need for urgent patching and threat hunting.
Key Takeaways
- CVE-2026-59310 is a critical RCE in VMware vCenter Syslog Server that is being actively exploited in the wild.
- Attackers leverage the flaw to deploy a reverse SSH tool, enabling persistent remote access to compromised vCenter instances.
- Organizations running affected VMware vCenter versions should apply the vendor-supplied patch immediately and audit for indicators of compromise.