CVE-2026-59310: Active Campaign Exploits VMware vCenter Syslog Server - Reverse SSH for Persistence

In this saga : Failles KVM et virtualisation Linux : l'hyperviseur sous pression· Episode 2/2

Cybersecurity Aug 14, 2026Add to bookmarks

Cybersecurity

A critical RCE flaw in VMware vCenter Syslog Server is being exploited in an active campaign. Attackers are deploying reverse SSH to maintain persistent access to hypervisors. The string of virtualization vulnerabilities continues.

What - CVE-2026-59310

A critical RCE (Remote Code Execution) vulnerability in VMware vCenter’s Syslog Server is being actively exploited in the wild. Attackers are deploying a reverse SSH tool to maintain persistent remote access to compromised hypervisors. The flaw was recently patched by Broadcom/VMware, but unpatched systems remain exposed.

Who is affected

Any organization running VMware vCenter with the Syslog Server enabled—effectively most enterprise datacenters on the VMware stack. The Syslog Server is often left enabled by default for centralized log collection.

Analysis

The attack vector is particularly concerning: the Syslog Server is a management-plane component, frequently accessible from network segments broader than the VMs themselves. A threat actor who compromises this service can pivot to the host hypervisor and from there to all hosted virtual machines.

The deployment of reverse SSH—rather than a simple webshell—signals a persistence and stealthy command-and-control (C2) approach: the outbound connection initiated from the target often bypasses inbound firewall rules, and SSH traffic blends into normal network-log noise.

This pattern continues the thread we’ve been tracking on virtualization vulnerabilities: after the initial Zapscape flaw (CVE-2026-64561) in Linux KVM, VMware vCenter’s management layer is now under active pressure. The attack surface of enterprise virtualization is expanding at an alarming rate.

Maximum Severity

CVE-2026-59310 - critical severity. Active exploitation documented in campaigns per BleepingComputer. Patch available from Broadcom/VMware.

What to do now

  1. Patch immediately: apply the Broadcom fix for CVE-2026-59310 across all vCenter deployments.
  2. Disable the Syslog Server if you do not actively use it.
  3. Audit outbound SSH connections from your ESXi hypervisors: any SSH egress to an unreferenced external IP is suspicious.
  4. Check IOCs (Indicators of Compromise) published with the Broadcom advisory to determine if your infrastructure may have been impacted before patching.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

9 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

Failles KVM et virtualisation Linux : l'hyperviseur sous pression

  1. 1Zapscape (CVE-2026-64561): A 6-Year-Old KVM Vulnerability Enables VM Escape to Linux Host08/08/2026
  2. 2CVE-2026-59310: Active Campaign Exploits VMware vCenter Syslog Server - Reverse SSH for Persistence14/08/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information