Back to advisories

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on victim infrastructure. Any unpatched vCenter instance is at immediate risk of RCE and lateral movement.

CRITICALAdvisoryAug 14, 2026
Action required
Immediately patch all VMware vCenter instances to the latest version. In parallel, hunt for reverse SSH connections and suspicious syslog service activity on vCenter servers. Block or isolate any vCenter system that cannot be patched within 24 hours.
Affected products
VMware vCenter Syslog ServerVMwareBroadcom