Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
Brief
An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks.
Tracked as CVE-2026-59310 , the flaw is a maximum-severity directory-traversal vulnerability residing in the VMware vCenter Syslog server component.
VMware vCenter Systems Exploited for Remote Access
Broadcom released a security advisory warning that unauthenticated attackers with network access to an exposed vCenter instance can exploit the vulnerability to achieve remote code execution (RCE) with system privileges.
