← Back to Feed

Critical VMware vCenter RCE flaw exploited for reverse SSH access

CVE-2026-59310

August 13, 2026 · BleepingComputer · Severity: CRITICAL

A critical remote code execution vulnerability in VMware vCenter Syslog Server, tracked as CVE-2026-59310, is being actively exploited in a campaign that installs a reverse SSH tool for persistent remote access. Although the vulnerability has been patched, attackers are using it to gain RCE and maintain long-term access to compromised vCenter instances, emphasizing the need for urgent patching and threat hunting.

Key Takeaways

  • CVE-2026-59310 is a critical RCE in VMware vCenter Syslog Server that is being actively exploited in the wild.
  • Attackers leverage the flaw to deploy a reverse SSH tool, enabling persistent remote access to compromised vCenter instances.
  • Organizations running affected VMware vCenter versions should apply the vendor-supplied patch immediately and audit for indicators of compromise.
☕ Buy a Coffee