Cybersecurity Aug 14, 2026Add to bookmarks
A critical RCE flaw in VMware vCenter Syslog Server is being exploited in an active campaign. Attackers are deploying reverse SSH to maintain persistent access to hypervisors. The string of virtualization vulnerabilities continues.
A critical RCE (Remote Code Execution) vulnerability in VMware vCenter’s Syslog Server is being actively exploited in the wild. Attackers are deploying a reverse SSH tool to maintain persistent remote access to compromised hypervisors. The flaw was recently patched by Broadcom/VMware, but unpatched systems remain exposed.
Any organization running VMware vCenter with the Syslog Server enabled—effectively most enterprise datacenters on the VMware stack. The Syslog Server is often left enabled by default for centralized log collection.
The attack vector is particularly concerning: the Syslog Server is a management-plane component, frequently accessible from network segments broader than the VMs themselves. A threat actor who compromises this service can pivot to the host hypervisor and from there to all hosted virtual machines.
The deployment of reverse SSH—rather than a simple webshell—signals a persistence and stealthy command-and-control (C2) approach: the outbound connection initiated from the target often bypasses inbound firewall rules, and SSH traffic blends into normal network-log noise.
This pattern continues the thread we’ve been tracking on virtualization vulnerabilities: after the initial Zapscape flaw (CVE-2026-64561) in Linux KVM, VMware vCenter’s management layer is now under active pressure. The attack surface of enterprise virtualization is expanding at an alarming rate.
CVE-2026-59310 - critical severity. Active exploitation documented in campaigns per BleepingComputer. Patch available from Broadcom/VMware.
Article produced by artificial intelligence, reviewed under human editorial control.
Failles KVM et virtualisation Linux : l'hyperviseur sous pression