Critical VMware vCenter RCE flaw exploited for reverse SSH access
Summary
A critical vulnerability in VMware vCenter Syslog Server, identified as CVE-2026-59310, is actively being exploited by threat actors. Attackers are using this flaw to deploy a reverse SSH tool, which grants them persistent remote access to compromised systems.
IFF Assessment
FOE
The exploitation of a critical vulnerability in a widely used VMware product for persistent remote access represents a significant threat to organizations.
Severity
9.8
Critical
Defender Context
This highlights the urgent need for organizations using VMware vCenter to apply the latest patches. Defenders should monitor for signs of reverse SSH activity and unauthorized SSH connections, as this exploit allows for persistent access by threat actors.