A critical security flaw in VMware vCenter, identified as CVE-2026-59310, is currently being exploited by threat actors, according to rapid incident response firm Quirso. This vulnerability, which has a CVSS score of 9.8, involves a directory traversal issue in the Syslog server that can lead to remote code execution. Broadcom addressed this flaw on July 29, alongside four other security issues in different VMware products. Despite the patch, an advanced persistent threat group is targeting web-accessible VMware vCenter servers vulnerable to this flaw, using a reverse shell technique for persistent system access.

Quirso's research has found over 360 victim IP addresses across 47 countries, with significant numbers located in Germany, the United States, Turkey, Iran, and France. It's important to note that an IP address does not necessarily indicate a specific organization or physical system since some belong to hosting providers or cloud networks. The exploitation activity was observed to start on August 3, with 340 IP addresses establishing connections to the attackers' infrastructure by August 5.

After the initial breach, the attackers deployed the open source SSH reverse shell framework known as reverse_ssh. This framework allows for an outbound control connection from compromised systems, sidestepping security measures that typically block incoming connections. To help detect this malicious activity, Quirso released a general YARA rule for identifying reverse_ssh builds. Organizations with publicly accessible vCenter systems are advised to confirm any detections by checking for unauthorized software installations and unexpected outbound connections or executions.