VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update
Brief
A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310 , a critical path traversal bug in the Syslog Server, to run commands as root without a normal login.
The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP addresses in 47 countries, with technology, research, education and telecommunications environments among the sectors exposed.
The scale illustrates why vCenter management systems are such attractive targets.
QUIRSO GmbH said in a report shared with Cyber Security News (CSN) that it investigated a compromise where the intrusion progressed from likely unauthenticated code execution to persistent access, account creation, ESXi control and ransomware.
