THREAT actors are exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, disclosed on July 29 and patched by Broadcom. The flaw, rated 9.8 on the CVSS scale, is associated with directory traversal in the Syslog server allowing remote code execution. Advanced persistent threat (APT) groups have targeted vulnerable servers, with Quirso identifying over 360 compromised IP addresses across 47 countries, predominantly in Germany, the US, Turkey, Iran, and France.
Exploitation began shortly after the bug's disclosure, with attackers utilizing a reverse SSH shell for persistent access. Organizations are advised to validate detections to mitigate risks.