Critical VMware vCenter RCE flaw exploited for reverse SSH access

Summary

A critical vulnerability in VMware vCenter Syslog Server, identified as CVE-2026-59310, is actively being exploited by threat actors. Attackers are using this flaw to deploy a reverse SSH tool, which grants them persistent remote access to compromised systems.

IFF Assessment

FOE

The exploitation of a critical vulnerability in a widely used VMware product for persistent remote access represents a significant threat to organizations.

Severity

9.8 Critical

Defender Context

This highlights the urgent need for organizations using VMware vCenter to apply the latest patches. Defenders should monitor for signs of reverse SSH activity and unauthorized SSH connections, as this exploit allows for persistent access by threat actors.

Read Full Story →